FAIL › dossier
Ubiquiti
VENDOR· dossier confidence 50%
Ubiquiti is a network security vendor with a documented track record of high-severity remote code execution and system compromise vulnerabilities in its UniFi OS and AirOS platforms, including multiple critical flaws actively exploited in the wild.
PROFILE
Categorynetwork securityWhat they doUbiquiti provides networking hardware and software solutions for enterprise and consumer markets.
SECURITY POSTURE
Ubiquiti has a history of high-severity remote code execution and system compromise vulnerabilities in its UniFi OS and AirOS platforms, with multiple critical flaws exploited in the wild.
Notable failures
- CVE-2010-5330 command injection in AirOS
- CVE-2026-34910 remote command injection in UniFi OS
- CVE-2026-34909 path traversal in UniFi OS
Patterns: repeated unpatched edge-device RCEs; improper input validation in network management software
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-15 | CVE-2010-5330 | high | Ubiquiti AirOS devices suffered a command injection flaw via stainfo.cgi that was actively exploited in the wild. |
| 2026-06-23 | CVE-2026-34910 | high | Ubiquiti UniFi OS allows remote command injection via improper input validation, enabling attackers to execute arbitrary commands on the network. |
| 2026-06-23 | CVE-2026-34909 | high | Ubiquiti UniFi OS path traversal vulnerability allows attackers to access and manipulate system files to compromise underlying accounts. |
| 2026-06-23 | CVE-2026-34908 | high | Ubiquiti UniFi OS allows unauthorized system changes via improper access control when network access is compromised. |
Open questions: Ubiquiti's current patching cadence for UniFi OS · Whether recent vulnerabilities have been addressed in subsequent firmware releases
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 03:57:54.818910+00:00