Ubiquiti patches critical flaws enabling remote code execution on UniFi devices

Ubiquiti has released security updates to address three high-severity vulnerabilities that allow remote attackers to execute commands without credentials on UniFi Protect, UniFi OS, and UniFi Talk, amid ongoing concerns over exploitation and platform stability.

Ubiquiti has issued security updates for three maximum-severity flaws that could let remote attackers run commands on affected equipment without needing credentials, according to reporting by BleepingComputer. The bugs affect UniFi Protect, UniFi OS and UniFi Talk, and the company says the weaknesses can be exploited with low complexity and no user interaction. Ubiquiti has not said whether the issues were abused before patching.

The disclosure adds to a run of serious findings affecting the vendor’s platform. Ubiquiti had already moved to fix a separate set of critical issues across a broad range of products, while security researchers have repeatedly shown how weaknesses in UniFi OS can be chained to bypass authentication and reach code-execution paths. CISA has also placed earlier Ubiquiti flaws in its Known Exploited Vulnerabilities catalogue after reports of active abuse, underlining the appeal of these devices to botnet operators and other threat actors.

For administrators, the immediate priority is patching and checking exposure. Ubiquiti says updates are available for the affected products, and defenders should treat internet-facing installations as high-risk until they are confirmed fully current. In practical terms, that means applying vendor fixes promptly, reducing external access where possible and reviewing whether any device may have been reachable during the window before remediation.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.