Executive brief
UniFi gateways are network access points that control internet connectivity and security for organizations. A flaw in certain gateway devices allows an attacker on the network to crash the gateway by writing data to memory in an uncontrolled manner, causing a denial of service. An organization would lose network connectivity until the device restarts or is manually recovered.
Technical details
An out-of-bounds write vulnerability in UniFi gateway devices allows an attacker with network access to trigger a denial of service condition by writing beyond allocated memory boundaries. The vulnerability does not provide code execution or data exfiltration, only availability impact. A patch is available from Ubiquiti.
Affected products
- Ubiquiti UniFi Gateway
Timeline
- 2026-09-22: disclosed