Uni's vulnerability footprint centers on network infrastructure and management appliances, including Cloud Key and UniFi Dream Machine products from its portfolio. The observed weakness class concentrates on cross-site request forgery, a web-interface input-handling issue endemic to management interfaces and network appliance administration consoles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uni over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28361MEDIUM A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi O | May 11, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uni.
Media articles that mention a CVE ID that affects a product developed by Uni — matched by CVE ID, not by vendor name.