CVE-2026-54402

Published Jul 2, 2026

Last updated 17 days ago

Overview

Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
Source
support@hackerone.com
NVD status
Analyzed
Products
unifi_os_server, unifi_dream_machine_firmware, unifi_dream_machine_pro_firmware, unifi_dream_machine_special_edition_firmware, unifi_dream_machine_pro_max_firmware, unifi_dream_machine_beast_firmware, enterprise_fortress_gateway_firmware, unifi_dream_router_firmware, unifi_dream_wall_firmware, unifi_dream_router_7_firmware, unifi_express_7_firmware, unifi_cloudkey_firmware, unifi_cloud_key_plus_firmware, unifi_cloudkey_enterprise_firmware, unifi_network_video_recorder_firmware, unifi_network_video_recorder_pro_firmware, unifi_network_video_recorder_instant_firmware, enterprise_network_video_recorder_core_firmware, unifi_network_video_recorder_g2_firmware, unifi_network_video_recorder_g2_pro_firmware, unifi_cloud_gateway_ultra_firmware, unifi_cloud_gateway_max_firmware, unifi_cloud_gateway_industrial_firmware, unifi_cloud_gateway_fiber_firmware, unas_2_firmware, unas_4_firmware, unas_pro_firmware, unas_pro_4_firmware, unas_pro_8_firmware, enterprise_firewall_core_firmware, unifi_dream_router_5g_max_firmware, enterprise_network_video_recorder_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-20
nvd@nist.gov
CWE-77

Social media

Hype score
Not currently trending

Configurations