Executive brief
UniFi Gateway devices contain an out-of-bounds write vulnerability that allows a network-adjacent attacker to trigger a denial of service, rendering the gateway temporarily unavailable. An attacker with network access could crash or freeze the device, disrupting network connectivity for all users relying on it.
Technical details
An out-of-bounds write vulnerability exists in UniFi Gateway firmware, exploitable via network access without authentication. Successful exploitation causes a denial of service by crashing or hanging the gateway process. The vulnerability requires the attacker to be on the same network or have adjacent network access to the device.
Affected products
- Ubiquiti UniFi Gateway
Timeline
- 2026-09-22: disclosed