CVE-2024-22054: Ubiquiti UniFi Uap Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi Access Points to Version 6.6.55 or later. Update UniFi Switches to Version 6.6.61 or later. Update UniFi LTE Backup to Version 6.6.57 or later. Update UniFi Express to Version 3.2.5 or later.
Affected products
- Ubiquiti UniFi Uap Firmware: before 6.6.55 (fixed in 6.6.55)
- Ubiquiti Inc UniFi Access Points: before 6.6.55 (fixed in 6.6.55)
- Ubiquiti Inc UniFi Express: before 3.2.5 (fixed in 3.2.5)
- Ubiquiti Inc UniFi Lte Backup: before 6.6.57 (fixed in 6.6.57)
- Ubiquiti Inc UniFi Switches: before 6.6.61 (fixed in 6.6.61)
Published 2024-02-20. Last modified 2026-06-17.