Vulnerabilidades em Ubiquiti Inc

110 resultados
Análise Vexday

Com 3 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Ubiquiti Inc apresenta uma taxa de exploração 11,9 vezes acima da média geral, o que indica histórico desproporcional de vulnerabilidades efetivamente aproveitadas por agentes maliciosos. Das 56 CVEs catalogadas, 22 são classificadas como críticas, e 15 surgiram nos últimos 90 dias, sugerindo ritmo acelerado de descoberta recente que merece acompanhamento contínuo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que tende a viabilizar diferentes classes de ataque quando não mitigado sistematicamente. A CVE-2026-34910 se destaca como a ameaça ativa mais grave no momento, com EPSS de 0,7856 — valor que indica alta probabilidade de exploração —, e deve ser tratada com prioridade máxima por equipes que operam equipamentos Ubiquiti.

CVE-2025-24290CRITICALMultiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor wEPSS 0.3%CVE-2026-47369CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain deEPSS 0.3%CVE-2025-27216HIGHMultiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to eEPSS 0.3%CVE-2026-77549CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraEPSS 0.3%CVE-2026-77532CRITICALA malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwiEPSS 0.3%CVE-2026-55110HIGHA malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration EPSS 0.3%CVE-2026-48610HIGHUnder certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found EPSS 0.3%CVE-2025-27215HIGHAn Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsuEPSS 0.3%CVE-2026-77541CRITICALA malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi NetwoEPSS 0.3%CVE-2025-59467HIGHA Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation EPSS 0.3%CVE-2025-27213MEDIUMAn Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug BEPSS 0.2%CVE-2026-77534CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain deviEPSS 0.2%CVE-2026-77553CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi AccessEPSS 0.2%CVE-2026-77536CRITICALA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain deviEPSS 0.2%CVE-2025-23117MEDIUMAn Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras aEPSS 0.2%CVE-2026-77538HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to esEPSS 0.2%CVE-2025-52663HIGHA vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This iEPSS 0.2%CVE-2026-77551CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UnEPSS 0.2%CVE-2026-77545CRITICALA malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability fEPSS 0.2%CVE-2025-23091MEDIUMAn Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-EPSS 0.2%