Executive brief
Ubiquiti UniFi Gateway devices are network appliances that manage connectivity and routing for businesses. An attacker on the network could exploit an out-of-bounds read vulnerability to crash the gateway, interrupting network service and affecting all devices it protects. This requires network access but no authentication.
Technical details
An out-of-bounds read vulnerability in UniFi Gateway devices allows a network-adjacent attacker to trigger a denial of service condition. The vulnerability is exploitable by a malicious actor with network access to the device, without requiring authentication or user interaction. Successful exploitation results in a crash or unavailability of the gateway.
Affected products
- Ubiquiti UniFi Gateway certain versions
Timeline
- 2026-09-22: disclosed