CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Weakness-Klassen (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
- Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red podría explotar una vulnerabilidad de validación de entrada incorrecta encontrada en dispositivos UniFi OS para ejecutar una inyección de comandos.
- Initial Analysis2026-06-24 14:49 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
- CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*
- CVE Modified2026-06-24 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-34910","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-34910","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE CISA KEV Update2026-06-23 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-06-23
- Due Date: 2026-06-23
- Required Action: 2026-06-23
- Vulnerability Name: 2026-06-23
- CVE Modified2026-06-23 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910
- Reference: https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/
- SSVC: {"id":"CVE-2026-34910","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-34910","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
Beschreibung
Ein böswilliger Akteur mit Zugriff auf das Netzwerk könnte eine Schwachstelle in der unzureichenden Eingabe-Validierung in UniFi-OS-Geräten ausnutzen, um eine Befehls-Injektion auszuführen.
Quelle: EUVD
Betroffene Betriebssysteme
other
ui / enterprise_fortress_gateway_firmware
other
ui / enterprise_network_video_recorder_core_firmware
other
ui / enterprise_network_video_recorder_firmware
other
ui / unas_2_firmware
other
ui / unas_4_firmware
other
ui / unas_pro_4_firmware
other
ui / unas_pro_8_firmware
other
ui / unas_pro_firmware
other
ui / unifi_cloud_gateway_fiber_firmware
other
ui / unifi_cloud_gateway_industrial_firmware
other
ui / unifi_cloud_gateway_max_firmware
other
ui / unifi_cloud_gateway_ultra_firmware
other
ui / unifi_cloud_key_plus_firmware
other
ui / unifi_cloudkey_enterprise_firmware
other
ui / unifi_cloudkey_firmware
other
ui / unifi_dream_machine_beast_firmware
other
ui / unifi_dream_machine_firmware
other
ui / unifi_dream_machine_pro_firmware
other
ui / unifi_dream_machine_pro_max_firmware
other
ui / unifi_dream_machine_special_edition_firmware
other
ui / unifi_dream_router_5g_max_firmware
other
ui / unifi_dream_router_7_firmware
other
ui / unifi_dream_router_firmware
other
ui / unifi_dream_wall_firmware
Öffentliche Exploit-Referenzen
Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.
Quellen & Referenzen
Verknüpfte Empfehlungen
- sans-newsbites-mail2026-07-02 00:00 UTCUbiquiti Patches Critical UniFi Vulnerabilities
- sans-newsbites-mail2026-06-24 00:00 UTCKEV: Lantronix, Ubiquiti UniFi OS, PTC Windchill and FlexPLM, and Cisco Unified Communications Manager
- sans-newsbites-mail2026-05-21 00:00 UTCPatch UniFi OS for Three CVSS 10.0 Flaws