Skip to content
COOEY

FAIL › dossier

Ubiquiti

VENDOR

· dossier confidence 50%

Ubiquiti is a network security vendor with a documented track record of high-severity remote code execution and system compromise vulnerabilities in its UniFi OS and AirOS platforms, including multiple critical flaws actively exploited in the wild.

PROFILE
Categorynetwork securityWhat they doUbiquiti provides networking hardware and software solutions for enterprise and consumer markets.
SECURITY POSTURE

Ubiquiti has a history of high-severity remote code execution and system compromise vulnerabilities in its UniFi OS and AirOS platforms, with multiple critical flaws exploited in the wild.

Notable failures
  • CVE-2010-5330 command injection in AirOS
  • CVE-2026-34910 remote command injection in UniFi OS
  • CVE-2026-34909 path traversal in UniFi OS
Patterns: repeated unpatched edge-device RCEs; improper input validation in network management software
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2022-04-15 CVE-2010-5330 high Ubiquiti AirOS devices suffered a command injection flaw via stainfo.cgi that was actively exploited in the wild.
2026-06-23 CVE-2026-34910 high Ubiquiti UniFi OS allows remote command injection via improper input validation, enabling attackers to execute arbitrary commands on the network.
2026-06-23 CVE-2026-34909 high Ubiquiti UniFi OS path traversal vulnerability allows attackers to access and manipulate system files to compromise underlying accounts.
2026-06-23 CVE-2026-34908 high Ubiquiti UniFi OS allows unauthorized system changes via improper access control when network access is compromised.
Open questions: Ubiquiti's current patching cadence for UniFi OS · Whether recent vulnerabilities have been addressed in subsequent firmware releases
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 03:57:54.818910+00:00