Vulnerabilidades en Ubiquiti Inc

110 resultados
Análisis Vexday

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2025-27214CRITICALA Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical oEPSS 0.4%CVE-2026-77538HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to esEPSS 0.4%CVE-2026-77545CRITICALA malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability fEPSS 0.4%CVE-2026-55119HIGHA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk AEPSS 0.4%CVE-2026-21639HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2026-77551CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UnEPSS 0.4%CVE-2026-48610HIGHUnder certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found EPSS 0.4%CVE-2026-55113HIGHA malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk ApplicatioEPSS 0.4%CVE-2026-55118HIGHA malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerabilEPSS 0.4%CVE-2026-56842HIGHA malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UnEPSS 0.4%CVE-2026-22566HIGHAn Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credeEPSS 0.4%CVE-2026-22559HIGHAn Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is sociaEPSS 0.4%CVE-2026-55112HIGHA malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerEPSS 0.4%CVE-2025-23164MEDIUMA misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share EPSS 0.4%CVE-2024-29208LOWAn Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the EPSS 0.3%CVE-2025-24292MEDIUMA misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OEPSS 0.3%CVE-2024-29207HIGHAn Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. AffeEPSS 0.3%CVE-2025-24290CRITICALMultiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor wEPSS 0.3%CVE-2025-27216HIGHMultiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to eEPSS 0.3%CVE-2026-55110HIGHA malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration EPSS 0.3%