Critical CVSS 10.0 vulnerability in Ubiquiti UniFi OS allows unauthenticated network actors to gain full control. Patch to version 5.1.12 or higher.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| unifi_os_server | * | 5.0.8 | vulnerable |
| unifi_cloud_gateway_industrial_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_industrial | - | - | unaffected |
| unifi_dream_machine_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine | - | - | unaffected |
| unifi_dream_machine_pro_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine_pro | - | - | unaffected |
| unifi_dream_machine_special_edition_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine_special_edition | - | - | unaffected |
| unifi_dream_machine_pro_max_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine_pro_max | - | - | unaffected |
| enterprise_fortress_gateway_firmware | * | 5.1.12 | vulnerable |
| enterprise_fortress_gateway | - | - | unaffected |
| unifi_dream_wall_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_wall | - | - | unaffected |
| unifi_dream_router_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_router | - | - | unaffected |
| unifi_dream_router_7_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_router_7 | - | - | unaffected |
| unifi_express_7_firmware | * | 5.1.12 | vulnerable |
| unifi_express_7 | - | - | unaffected |
| unifi_network_video_recorder_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder | - | - | unaffected |
| unifi_network_video_recorder_pro_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_pro | - | - | unaffected |
| unifi_network_video_recorder_instant_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_instant | - | - | unaffected |
| enterprise_network_video_recorder_firmware | * | 5.1.12 | vulnerable |
| enterprise_network_video_recorder | - | - | unaffected |
| unifi_cloud_gateway_ultra_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_ultra | - | - | unaffected |
| unifi_cloud_gateway_max_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_max | - | - | unaffected |
| unifi_cloud_gateway_fiber_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_fiber | - | - | unaffected |
| unifi_dream_router_5g_max_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_router_5g_max | - | - | unaffected |
| enterprise_network_video_recorder_core_firmware | * | 5.1.12 | vulnerable |
| enterprise_network_video_recorder_core | - | - | unaffected |
| unifi_cloud_key_plus_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_key_plus | - | - | unaffected |
| unifi_cloudkey_firmware | * | 5.1.12 | vulnerable |
| unifi_cloudkey | - | - | unaffected |
| unifi_cloudkey_enterprise_firmware | * | 5.1.12 | vulnerable |
| unifi_cloudkey_enterprise | - | - | unaffected |
| unifi_network_video_recorder_g2_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_g2 | - | - | unaffected |
| unifi_network_video_recorder_g2_pro_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_g2_pro | - | - | unaffected |
| unifi_dream_machine_beast_firmware | * | 5.1.11 | vulnerable |
| unifi_dream_machine_beast | - | - | unaffected |
| unas_2_firmware | * | 5.1.10 | vulnerable |
| unas_2 | - | - | unaffected |
| unas_4_firmware | * | 5.1.10 | vulnerable |
| unas_4 | - | - | unaffected |
| unas_pro_firmware | * | 5.1.10 | vulnerable |
| unas_pro | - | - | unaffected |
| unas_pro_4_firmware | * | 5.1.10 | vulnerable |
| unas_pro_4 | - | - | unaffected |
| unas_pro_8_firmware | * | 5.1.10 | vulnerable |
| unas_pro_8 | - | - | unaffected |
Download and install the latest firmware updates directly from the Ubiquiti Downloads portal or via the UniFi OS management console to address the improper access control flaw.
Ensure UniFi OS is updated to version 5.1.12 or higher for most gateways and NVRs, version 5.1.11 for UDM Beast, version 5.1.10 for UNAS models, and 5.0.8 for server components.
Discontinue exposure of UniFi OS management interfaces to the public internet. Use a VPN or local management VLAN to restrict access to authorized administrative IP addresses only.
Review UniFi OS audit logs for unauthorized configuration changes, the creation of unrecognized administrator accounts, or unexpected outbound traffic from the gateway device.
Detection should focus on identifying unauthorized management traffic. Monitor network logs for unusual connections to ports 443 or 8443 originating from untrusted IP addresses. Inspect UniFi OS system logs for successful logins from unknown sources or unauthorized configuration changes. Additionally, use configuration drift detection to identify the addition of rogue SSH keys or new administrative users created without authorization.
Experience superior visibility and a simpler approach to cyber risk management