Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.
📦
unifi_dream_router
Vendor: ui
Actively Exploited
3
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
3
Remote Access
Total CVEs
16
Total Indexed
Avg. EPSS
20.03%
Exploit Prob.
Security Vulnerability Index
Page 2 / 2
5.3
CVSS
Severity: MEDIUM
6.5
CVSS
A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.
Severity: MEDIUM