Executive brief
Ubiquiti UniFi OS, the software used to manage various networking and security devices like routers and video recorders, is affected by a security flaw. An attacker who already has a low-level account on the network could use this vulnerability to gain full administrative control over the device. This could allow them to access sensitive data, disrupt network operations, or compromise connected security cameras and storage systems.
Technical details
A series of authenticated SQL injection (CWE-89) vulnerabilities exist in Ubiquiti UniFi OS across multiple hardware platforms. The vulnerability is exploitable by a remote attacker with low-privileged credentials (PR:L) over the network (AV:N). By injecting malicious SQL commands, an attacker can bypass intended access controls to escalate their privileges within the UniFi OS environment. The issue affects various product lines including Dream Machines, Cloud Keys, and Network Video Recorders running versions prior to 5.1.19. Users are advised to update to UniFi OS version 5.1.19 or later to mitigate these risks.
Affected products
- Ubiquiti Inc UniFi OS Server < 5.1.19
- Ubiquiti Inc Dream Machines < 5.1.19
- Ubiquiti Inc Enterprise Fortress Gateway < 5.1.19
- Ubiquiti Inc Dream Wall < 5.1.19
- Ubiquiti Inc Dream Routers < 5.1.19
- Ubiquiti Inc Express 7 < 5.1.19
- Ubiquiti Inc Cloud Keys < 5.1.19
- Ubiquiti Inc Network Video Recorders < 5.1.19
- Ubiquiti Inc Enterprise Video Recorders < 5.1.19
- Ubiquiti Inc Cloud Gateways < 5.1.19
- Ubiquiti Inc Network Attached Storage < 5.1.19
- Ubiquiti Inc Enterprise Firewall Core < 5.1.19
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory