Vulnerabilidades em Ubiquiti Inc

110 resultados
Análise Vexday

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2026-21634MEDIUMA malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery prEPSS 0.4%CVE-2026-22564CRITICALAn Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthoriEPSS 0.4%CVE-2026-21638HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2026-55116CRITICALA malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerabilityEPSS 0.4%CVE-2025-27217CRITICALA Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside oEPSS 0.4%CVE-2025-27214CRITICALA Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical oEPSS 0.4%CVE-2026-55119HIGHA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk AEPSS 0.4%CVE-2026-21639HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2026-55113HIGHA malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk ApplicatioEPSS 0.4%CVE-2026-55118HIGHA malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerabilEPSS 0.4%CVE-2026-56842HIGHA malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UnEPSS 0.4%CVE-2026-22566HIGHAn Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credeEPSS 0.4%CVE-2026-22559HIGHAn Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is sociaEPSS 0.4%CVE-2026-55112HIGHA malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerEPSS 0.4%CVE-2026-47368HIGHA malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtaiEPSS 0.4%CVE-2025-23164MEDIUMA misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share EPSS 0.4%CVE-2024-29208LOWAn Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the EPSS 0.3%CVE-2025-24292MEDIUMA misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OEPSS 0.3%CVE-2026-77557CRITICALA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalatEPSS 0.3%CVE-2024-29207HIGHAn Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. AffeEPSS 0.3%