Critical command injection vulnerability (CVSS 10.0) in Ubiquiti UniFi OS devices. Actively exploited; immediate patching to version 5.1.12 is required.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| unifi_os_server | * | 5.0.8 | vulnerable |
| unifi_cloud_gateway_industrial_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_industrial | - | - | unaffected |
| unifi_dream_machine_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine | - | - | unaffected |
| unifi_dream_machine_pro_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine_pro | - | - | unaffected |
| unifi_dream_machine_special_edition_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine_special_edition | - | - | unaffected |
| unifi_dream_machine_pro_max_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_machine_pro_max | - | - | unaffected |
| enterprise_fortress_gateway_firmware | * | 5.1.12 | vulnerable |
| enterprise_fortress_gateway | - | - | unaffected |
| unifi_dream_wall_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_wall | - | - | unaffected |
| unifi_dream_router_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_router | - | - | unaffected |
| unifi_dream_router_7_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_router_7 | - | - | unaffected |
| unifi_express_7_firmware | * | 5.1.12 | vulnerable |
| unifi_express_7 | - | - | unaffected |
| unifi_network_video_recorder_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder | - | - | unaffected |
| unifi_network_video_recorder_pro_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_pro | - | - | unaffected |
| unifi_network_video_recorder_instant_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_instant | - | - | unaffected |
| enterprise_network_video_recorder_firmware | * | 5.1.12 | vulnerable |
| enterprise_network_video_recorder | - | - | unaffected |
| unifi_cloud_gateway_ultra_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_ultra | - | - | unaffected |
| unifi_cloud_gateway_max_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_max | - | - | unaffected |
| unifi_cloud_gateway_fiber_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_gateway_fiber | - | - | unaffected |
| unifi_dream_router_5g_max_firmware | * | 5.1.12 | vulnerable |
| unifi_dream_router_5g_max | - | - | unaffected |
| enterprise_network_video_recorder_core_firmware | * | 5.1.12 | vulnerable |
| enterprise_network_video_recorder_core | - | - | unaffected |
| unifi_cloud_key_plus_firmware | * | 5.1.12 | vulnerable |
| unifi_cloud_key_plus | - | - | unaffected |
| unifi_cloudkey_firmware | * | 5.1.12 | vulnerable |
| unifi_cloudkey | - | - | unaffected |
| unifi_cloudkey_enterprise_firmware | * | 5.1.12 | vulnerable |
| unifi_cloudkey_enterprise | - | - | unaffected |
| unifi_network_video_recorder_g2_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_g2 | - | - | unaffected |
| unifi_network_video_recorder_g2_pro_firmware | * | 5.1.12 | vulnerable |
| unifi_network_video_recorder_g2_pro | - | - | unaffected |
| unifi_dream_machine_beast_firmware | * | 5.1.11 | vulnerable |
| unifi_dream_machine_beast | - | - | unaffected |
| unas_2_firmware | * | 5.1.10 | vulnerable |
| unas_2 | - | - | unaffected |
| unas_4_firmware | * | 5.1.10 | vulnerable |
| unas_4 | - | - | unaffected |
| unas_pro_firmware | * | 5.1.10 | vulnerable |
| unas_pro | - | - | unaffected |
| unas_pro_4_firmware | * | 5.1.10 | vulnerable |
| unas_pro_4 | - | - | unaffected |
| unas_pro_8_firmware | * | 5.1.10 | vulnerable |
| unas_pro_8 | - | - | unaffected |
Ubiquiti has released security updates to address this improper input validation flaw. Administrators should immediately consult the Ubiquiti Security Advisory Bulletin 064 for specific firmware download links and deployment instructions for their hardware models.
Ensure all UniFi OS devices are updated to version 5.1.12 or later. Specific products like the UniFi OS Server must be updated to 5.0.8+, and UNAS devices should be updated to at least 5.1.10 to effectively mitigate the command injection risk.
Minimize exposure by ensuring management interfaces are not accessible from the public internet. Implement strict firewall rules and use a dedicated management VLAN or VPN to limit access to authorized administrative personnel only.
Review system logs for unusual shell activity or unauthorized configuration changes. Use network security monitoring tools to detect suspicious traffic patterns targeting UniFi OS management ports, specifically looking for command injection payloads.
To detect potential exploitation of CVE-2026-34910, monitor web server logs for suspicious input strings containing shell metacharacters (e.g., semicolons, pipes, or command substitution) targeting UniFi OS endpoints. Look for unexpected outbound network connections from UniFi devices, which may indicate a reverse shell. Additionally, audit process execution logs for unauthorized instances of shell interpreters spawned by the web management service.
Experience superior visibility and a simpler approach to cyber risk management