Vulnerabilidades em Ubiquiti Inc

104 resultados
Análise Vexday

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2026-47370CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 0.8%CVE-2026-47367CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID EnterpEPSS 0.8%CVE-2026-77535CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi NetEPSS 0.8%CVE-2026-77539CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS EPSS 0.8%CVE-2026-77542CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID EnterEPSS 0.8%CVE-2026-77540CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS EPSS 0.8%CVE-2026-77547CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 0.8%CVE-2026-77548CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi ProtEPSS 0.8%CVE-2026-77546CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 0.8%CVE-2026-77543CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi AcceEPSS 0.8%CVE-2024-42025HIGHA Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and eaEPSS 0.8%CVE-2026-22562CRITICALA malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write fEPSS 0.8%CVE-2026-54403HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypasEPSS 0.8%CVE-2025-23115CRITICALA Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi EPSS 0.7%CVE-2025-23119HIGHAn Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a maEPSS 0.7%CVE-2026-34911HIGHA malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to acEPSS 0.7%CVE-2025-48978HIGHAn Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with acEPSS 0.7%CVE-2026-54406HIGHA malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instancesEPSS 0.6%CVE-2025-27211HIGHAn Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with acEPSS 0.6%CVE-2026-54408HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byEPSS 0.6%