A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-06-12T02:27:43.642Z
Reserved: 2026-05-19T15:00:09.320Z
Link: CVE-2026-47370
No data.
Status : Received
Published: 2026-06-12T04:17:06.657
Modified: 2026-06-12T04:17:06.657
Link: CVE-2026-47370
No data.
OpenCVE Enrichment
Updated: 2026-06-12T04:30:04Z
Weaknesses