Ubiquiti
Vulnerabilities in Ubiquiti's UniFi product line — the switches, gateways, and access points that make up the physical layer of a lot of small businesses, campuses, and prosumer networks, often deployed once and rarely touched again.
UniFi Protect Application improper input validation — unauthenticated RCE
A CVSS 10.0 improper input validation flaw in Ubiquiti's UniFi Protect Application lets unauthenticated remote attackers execute arbitrary code with no user interaction. Fixed in UniFi Protect 7.2.105.
UniFi OS CRLF injection — authentication bypass
A CVSS 10.0 CRLF injection vulnerability in Ubiquiti's UniFi OS allows unauthenticated remote attackers to bypass authentication. Affects UniFi OS devices; patch version not yet publicly documented.
UniFi Talk command injection — unauthenticated remote code execution
A CVSS 10.0 command injection flaw in Ubiquiti's UniFi Talk VoIP application allows unauthenticated remote code execution via improper input validation. Fixed in UniFi Talk 5.3.2.
Ubiquiti UniFi Connect command injection (Bulletin 066)
Improper access control in Ubiquiti UniFi Connect ≤3.4.16 lets an attacker with network access execute command injection on the host device. CVSS 10.0. Fixed in 3.4.20.
Ubiquiti UniFi critical flaw (Bulletin 066)
Critical vulnerability in Ubiquiti UniFi products covered by Security Advisory Bulletin 066. CVSS 9.9. Part of a seven-CVE release batch headlined by a CVSS 10.0 command injection in UniFi Connect. Patch to 3.4.20 or later.
Ubiquiti UniFi critical flaw (Bulletin 066)
Critical vulnerability in Ubiquiti UniFi products covered by Security Advisory Bulletin 066. CVSS 9.9. Part of a seven-CVE release batch headlined by a CVSS 10.0 command injection in UniFi Connect. Patch to 3.4.20 or later.
Ubiquiti UniFi Access improper access control (Bulletin 066)
Improper access control in Ubiquiti UniFi Access lets a network attacker with existing high privileges escalate on the host device. CVSS 9.1. Fixed in the patch release accompanying Bulletin 066.
Ubiquiti UniFi OS Improper Access Control Vulnerability
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Ubiquiti UniFi OS Path Traversal Vulnerability
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Ubiquiti AirOS Command Injection Vulnerability
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

Ubiquiti Patches Three CVSS 10 Flaws in UniFi Products
Three CVSS 10 flaws in UniFi Protect, UniFi OS, and UniFi Talk allow unauthenticated remote exploitation with no user interaction. Patch all three immediately.

Ubiquiti Patches Max-Severity UniFi Connect Command Injection
Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.