Ui: community verdicts
5 notable / known-exploited Ui CVEs the community has triaged.
- CVE-2026-34910CRIT 10KEVEPSS 87%
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVE-2026-34908CRIT 10KEVEPSS 85%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
- CVE-2026-34909CRIT 10KEVEPSS 64%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
- CVE-2010-5330CRIT 9.8KEVEPSS 35%
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.
- CVE-2026-50746CRIT 10Real · low riskEPSS 3%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.