CVE-2026-34911

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the…

Severity
high
kein öffentlicher PoC bekannt
48.6 %
Hoch — Modell sieht erhöhte Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-22 00:43 UTC
CWE-22

Weakness-Klassen (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-23 16:10 UTC· nvd@nist.gov
    • Translation: Title: varios productos de Ubiquiti, Description: Un actor malicioso con acceso a la red y privilegios bajos podría explotar una vulnerabilidad de salto de ruta encontrada en dispositivos UniFi OS para acceder a archivos en el sistema subyacente que podrían ser manipulados para obtener información sensible.
  2. Initial Analysis2026-06-24 15:15 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:ui:unifi_os_server:*:*:*:*:*:*:*:* versions up to (excluding) 5.0.8
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_cloud_gateway_industrial_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_cloud_gateway_industrial:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:ui:unifi_dream_machine_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.12 OR cpe:2.3:h:ui:unifi_dream_machine_pro:-:*:*:*:*:*:*:*

Beschreibung

Ein böswilliger Akteur mit Netzwerkzugriff und niedrigen Privilegien könnte eine Pfad-Traversierung-Schwachstelle in UniFi-OS-Geräten ausnutzen, um auf Dateien des zugrunde liegenden Systems zuzugreifen, die manipuliert werden könnten, um sensible Informationen zu erlangen.

Quelle: EUVD

Betroffene Betriebssysteme

  • other

    ui / enterprise_fortress_gateway_firmware

  • other

    ui / enterprise_network_video_recorder_core_firmware

  • other

    ui / enterprise_network_video_recorder_firmware

  • other

    ui / unas_2_firmware

  • other

    ui / unas_4_firmware

  • other

    ui / unas_pro_4_firmware

  • other

    ui / unas_pro_8_firmware

  • other

    ui / unas_pro_firmware

  • other

    ui / unifi_cloud_gateway_fiber_firmware

  • other

    ui / unifi_cloud_gateway_industrial_firmware

  • other

    ui / unifi_cloud_gateway_max_firmware

  • other

    ui / unifi_cloud_gateway_ultra_firmware

  • other

    ui / unifi_cloud_key_plus_firmware

  • other

    ui / unifi_cloudkey_enterprise_firmware

  • other

    ui / unifi_cloudkey_firmware

  • other

    ui / unifi_dream_machine_beast_firmware

  • other

    ui / unifi_dream_machine_firmware

  • other

    ui / unifi_dream_machine_pro_firmware

  • other

    ui / unifi_dream_machine_pro_max_firmware

  • other

    ui / unifi_dream_machine_special_edition_firmware

  • other

    ui / unifi_dream_router_5g_max_firmware

  • other

    ui / unifi_dream_router_7_firmware

  • other

    ui / unifi_dream_router_firmware

  • other

    ui / unifi_dream_wall_firmware

Quellen & Referenzen

Verknüpfte Empfehlungen