Tag

Ubiquiti

All articles tagged with #ubiquiti

Ubiquiti rolls out fixes for critical UniFi vulnerabilities across core apps
technology1 month ago

Ubiquiti rolls out fixes for critical UniFi vulnerabilities across core apps

Ubiquiti released patches across UniFi Connect, Talk, Access, Protect, and UniFi OS to fix several critical flaws that could allow privilege escalation or remote command execution. The updates address multiple CVEs (e.g., CVE-2026-50746 for Connect; CVE-2026-50747 for Talk; CVE-2026-50748 and CVE-2026-54400 for Access; CVE-2026-55115 for Protect; CVE-2026-54402 and CVE-2026-55116 for OS) with fixed versions listed for each product. While there’s no confirmed exploitation in the wild, the U.S. CISA has flagged some UniFi OS flaws as weaponized, and historical activity like the MooBot botnet operation involved compromised Edge OS routers. Admins should upgrade to the patched releases to mitigate risk.

Ubiquiti patches seven UniFi OS flaws, including a critical UniFi Connect command-injection risk
security1 month ago

Ubiquiti patches seven UniFi OS flaws, including a critical UniFi Connect command-injection risk

Ubiquiti released security updates to fix seven critical UniFi OS vulnerabilities, including CVE-2026-50746 in the UniFi Connect App that could allow command injection; users should upgrade the UniFi Connect app to version 3.4.20+ and apply patches across UniFi Talk, UniFi Access, UniFi Protect, and the UniFi OS Server. The company notes several flaws can be exploited in low-complexity attacks with no user interaction. Threats note that more than 100,000 UniFi OS instances are exposed online (per Censys), though it isn’t clear how many are patched, honeypots, or otherwise secured. The report also references past CISA/FBI warnings and demonstrations of exploitation techniques in related Ubiquiti products.

Ubiquiti issues patches for three high-severity UniFi OS flaws exploitable remotely
security3 months ago

Ubiquiti issues patches for three high-severity UniFi OS flaws exploitable remotely

Ubiquiti released patches for three max-severity UniFi OS vulnerabilities (CVE-2026-34908/34909/34910) that allow remote attackers to change targeted systems, access underlying files, or inject commands, plus earlier patches for CVE-2026-33000 and CVE-2026-34911. The flaws can be exploited with low complexity on UniFi OS devices. Threat intel tracks nearly 100,000 internet-exposed UniFi OS endpoints (many in the U.S.); there’s no public confirmation of exploitation yet. The fixes were disclosed via HackerOne.

Privacy Breach: UniFi Devices Expose Private Videos to Unauthorized Users
technology2 years ago

Privacy Breach: UniFi Devices Expose Private Videos to Unauthorized Users

Users of UniFi devices from Ubiquiti have reported receiving private camera feeds and control over devices belonging to other users. The issue was caused by an upgrade to the UniFi Cloud infrastructure, which resulted in account mix-ups. During this time, some users received push notifications from consoles assigned to other users, and some users attempting to log into their accounts were granted temporary remote access to other accounts. Ubiquiti has fixed the issue and stated that the account mix-ups are no longer occurring. The incident has raised concerns about privacy and security for UniFi users.

Security Breach: Ubiquiti Users Expose Others' UniFi Routers and Cameras
technology2 years ago

Security Breach: Ubiquiti Users Expose Others' UniFi Routers and Cameras

Users of Ubiquiti networking devices have reported accessing other people's devices and notifications through the company's UniFi cloud services. Reports include receiving notifications from someone else's security camera and having access to other customers' devices and configurations. Ubiquiti has acknowledged the issue, stating that it was caused by a misconfiguration in an upgrade to the UniFi cloud infrastructure. The company believes that only twelve accounts were improperly accessed and has since fixed the issue. Affected account holders will be notified via email.

"Unifi Switch Succumbs to Harsh Texas Climate, Rest in Peace"
technology2 years ago

"Unifi Switch Succumbs to Harsh Texas Climate, Rest in Peace"

A Unifi 8-port POE switch, model US-8-150W, has finally died after years of withstanding extreme Texas outdoor temperatures. The switch, which played a crucial role in the author's home networking setup, survived daily temperatures of up to 120°F (50°C) for almost eight years. Despite being affected by a lightning strike, the switch continued to function, albeit with some ports and PoE capabilities disabled. The author replaced it with another US-8-150W and hopes to get another eight years out of the new switch.

Top Dividend Stocks with Double the Potential
finance2 years ago

Top Dividend Stocks with Double the Potential

Three dividend stocks with strong growth prospects in the technology sector are highlighted. Broadcom, despite recent declines in its shares, is expected to benefit from AI and an upcoming acquisition, with a current dividend yield of 2.3%. Microchip, with exposure to industrial computing and IoT, has a history of revenue growth and is increasing its dividend on a quarterly basis. Ubiquiti, known for its switches and WiFi equipment, has experienced a pullback but is expected to normalize and has a dividend yield of 1.6%.