Junglewise Threat Intelligence

CVE-2026-21639: Ubiquiti airMAX and airFiber remote code execution in airMAX protocol

CVE-2026-21639 · Severity: high · CVSS 8.8 · Published 2026-01-08

Vendors: Ubiquiti Inc.

Executive brief

Ubiquiti airMAX and airFiber devices, which are used to provide long-range wireless internet and network bridging, are vulnerable to a security flaw in their wireless protocol. An attacker within Wi-Fi range of these devices could take full control of the equipment without needing a password. This could lead to a total loss of network connectivity, interception of data passing through the bridge, or the device being used as a foothold to attack the rest of the internal network.

Technical details

This vulnerability involves a buffer overflow (CWE-120) and command injection (CWE-77) within the proprietary airMAX Wireless Protocol used by Ubiquiti devices. An unauthenticated attacker located within physical radio range (adjacent network) can exploit this flaw to execute arbitrary code with elevated privileges. The vulnerability affects multiple product lines including airMAX AC, airMAX M, and airFiber AF60 series. Patches have been released to address the issue, and users are advised to update to the latest firmware versions (airMAX AC 8.7.21+, airMAX M 6.3.24+, airFiber AF60-XG 1.2.3+, and airFiber AF60 2.6.8+).

Affected products

  • Ubiquiti Inc airMAX AC 8.7.20 and earlier
  • Ubiquiti Inc airMAX M 6.3.22 and earlier
  • Ubiquiti Inc airFiber AF60-XG 1.2.2 and earlier
  • Ubiquiti Inc airFiber AF60 2.6.7 and earlier

Timeline

  • 2026-01-08: disclosed
  • 2026-01-08: advisory

References