Ubiquiti Networks manufactures a focused line of network infrastructure products including EdgeOS-based routers, wireless access points, and managed switches that are widely deployed in enterprise and service-provider environments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with recurring exposure centered on privilege-escalation mechanisms, web-request forgery, path traversal, OS command injection, and permission-assignment flaws that affect network device management interfaces and remote-access attack surfaces. Defenders should prioritize patches for internet-facing management endpoints and inventory unsupported product generations; live severity and exploit-availability figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ubnt over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9266CRITICAL The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary file | Sep 5, 2018 | 9.8 | 81 | NO | YES |
CVE-2017-0934HIGH Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive in | Mar 22, 2018 | 8.8 | 29 | NO | NO |
CVE-2017-0933HIGH Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lur | Mar 22, 2018 | 8.0 | 24 | NO | NO |
CVE-2018-12591HIGH Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protection on the admin CLI, leading to code exec | Jun 20, 2018 | 7.2 | 22 | NO | NO |
CVE-2017-0932HIGH Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the input of the Feature functionalit | Mar 22, 2018 | 8.8 | 22 | NO | NO |
CVE-2017-0913MEDIUM Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a doc | Jul 3, 2018 | 4.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ubnt.
Media articles that mention a CVE ID that affects a product developed by Ubnt — matched by CVE ID, not by vendor name.