Ubiquiti patches three max severity security vulnerabilities
ID: e7c319d8-efda-5d32-acbd-d6940d057c5d
STIX ID: report--e7c319d8-efda-5d32-acbd-d6940d057c5d
Feed Name: Bleeping Computer
Ubiquiti released patches for three maximum-severity, unauthenticated remote vulnerabilities impacting UniFi Protect, UniFi Talk, and UniFi OS—rooted in improper input validation, CRLF injection, and command injection—and urged updating to fixed versions; the report highlights a large number of Internet-exposed UniFi instances and contextualizes the risk with past Ubiquiti-focused botnets and exploited vulnerabilities, though it notes no confirmed in-the-wild exploitation of these specific CVEs yet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
