A series of critical vulnerabilities—including three with “perfect” CVSSv3 10.0—can lead to account takeover and command injection on unpatched Unifi OS systems.
Ubiquiti’s advisory has details:
Patches are available and should be deployed ASAP.
A series of critical vulnerabilities—including three with “perfect” CVSSv3 10.0—can lead to account takeover and command injection on unpatched Unifi OS systems.
Ubiquiti’s advisory has details:
Patches are available and should be deployed ASAP.
I’m glad I’ve been avoiding that pop up to “upgrade” to unifi server for a few months now.
BishopFox has published a writeup on exploiting these vulnerabilities. Hope y’all patched!