Vulnerability index

Browse CVEs

113 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unifi Video MEDIUM 6.5
CVE-2020-8145

The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficie…

Fix: after 3.9.3
Fix from $1,600 2020-04-01
Airvision Controller HIGH 8.8
CVE-2014-2225

Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the au…

Fix: 3.2.1+
Fix from $1,950 2020-02-08
Edgeswitch HIGH 7.8
CVE-2020-8126

A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execut…

Fix: 1.7.1+
Fix from $1,950 2020-02-07
Unifi Video Controller HIGH 8.8
CVE-2019-15595

A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.

Fix: after 3.10.6
Fix from $1,950 2019-11-26
Er X Firmware HIGH 7.5
CVE-2019-16889EPSS 5%

Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker…

Fix: 2.0.3+
Fix from $1,950 2019-09-25
Unifi Controller HIGH 8.1
CVE-2019-5456

SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to…

Fix: after 5.10.21
Fix from $1,950 2019-07-30
Edgeswitch Firmware HIGH 7.2
CVE-2019-5446

Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.

Fix: 1.8.2+
Fix from $1,950 2019-07-10
Airos CRITICAL 9.8
CVE-2010-5330 KEVEPSS 35%

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitize…

Fix: 4.0.1 / 5.3.5+
Fix from $2,300 2019-06-11
Unifi Firmware MEDIUM 5.9
CVE-2018-5264

Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a …

No fix yet
Fix from $1,600 2019-06-07
Edgeos HIGH 7.2
CVE-2018-5265

Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/…

No fix yet
Fix from $1,950 2019-06-07
Aircam Firmware HIGH 7.5
CVE-2019-12727

On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be…

No fix yet
Fix from $1,950 2019-06-04
Unifi Video HIGH 8.8
CVE-2019-5430

In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration …

Fix: after 3.10.0
Fix from $1,950 2019-05-06
Edgeswitch X HIGH 8.8
CVE-2019-5424

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to…

Fix: after 1.1.0
Fix from $1,950 2019-04-10
Edgeswitch X HIGH 8.8
CVE-2019-5425

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the C…

Fix: after 1.1.0
Fix from $1,950 2019-04-10
Airos HIGH 7.5
CVE-2017-0938EPSS 21%

Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attack…

Fix: 1.9.7 / 6.0.7+
Fix from $1,950 2019-02-12
Airmax Ac Firmware CRITICAL 9.8
CVE-2015-9266EPSS 74%

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to …

Fix: 1.15 / 2.2.1+
Fix from $2,300 2018-09-05
Ucrm MEDIUM 5.4
CVE-2017-0912

Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary…

Fix: after 2.7.7
Fix from $1,600 2018-07-03
Edgeswitch Firmware HIGH 7.2
CVE-2018-12590

Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on th…

Fix: after 1.7.3
Fix from $1,950 2018-06-20
Edgeos HIGH 8.8
CVE-2017-0935

Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the fi…

Fix: after 1.9.1.1
Fix from $1,950 2018-03-22
Unifi Video HIGH 7.8
CVE-2016-6914

Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privilege…

Fix: 3.8.0+
Fix from $1,950 2017-12-27
Unifi Video MEDIUM 6.0
CVE-2014-2227

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 d…

Fix: after 2.1.3
Fix from $1,600 2014-07-25
Unifi Controller MEDIUM 6.1
CVE-2013-3572

Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remo…

Fix: 2.3.6+
Fix from $1,600 2013-12-31
Airvision Firmware HIGH 7.5
CVE-2013-1606EPSS 23%

Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allows remote attackers to execute…

Fix: after 1.1.5
Fix from $1,950 2013-07-18