Vulnerabilidades en Ubiquiti Inc

110 resultados
Análisis Vexday

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2026-77556HIGHA malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to exeEPSS 0.5%CVE-2026-95862HIGHA malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to exEPSS 0.5%CVE-2026-77544HIGHA malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to exEPSS 0.5%CVE-2026-77558HIGHA malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to exeEPSS 0.5%CVE-2026-54407HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byEPSS 0.5%CVE-2026-21633HIGHA malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery pEPSS 0.4%CVE-2026-54409HIGHA malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UnEPSS 0.4%CVE-2024-29206LOWAn Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported EPSS 0.4%CVE-2026-22565HIGHAn Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop rEPSS 0.4%CVE-2026-54401HIGHA malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges wiEPSS 0.4%CVE-2025-48979LOWAn Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.EPSS 0.4%CVE-2026-21634MEDIUMA malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery prEPSS 0.4%CVE-2026-22564CRITICALAn Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthoriEPSS 0.4%CVE-2026-77553CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi AccessEPSS 0.4%CVE-2026-77536CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain deviEPSS 0.4%CVE-2026-77534CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain deviEPSS 0.4%CVE-2026-77532CRITICALA malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwiEPSS 0.4%CVE-2026-21638HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2026-55116CRITICALA malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerabilityEPSS 0.4%CVE-2025-27217CRITICALA Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside oEPSS 0.4%