Executive brief
UniFi Talk is a communication application used within Ubiquiti networks. A critical vulnerability allows an attacker with network access to inject arbitrary commands that execute on the host device, potentially compromising the entire system and any data processed by the application.
Technical details
An Improper Input Validation vulnerability in the UniFi Talk Application enables Command Injection attacks. The vulnerability requires network access to the affected device but does not require authentication. An attacker can send crafted network packets containing malicious command sequences that bypass input validation filters, resulting in arbitrary command execution with the privileges of the UniFi Talk process. This allows complete compromise of the host system.
Affected products
- Ubiquiti UniFi Talk
Timeline
- 2026-08-26: disclosed