CVE-2024-54750: UI u6-Lr Firmware

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In Ubiquiti's view there is no vulnerability as the Hardcoded Password should be after setup not before.

Affected products

  • UI u6-Lr Firmware: version 6.6.65 only

Published 2024-12-06. Last modified 2026-06-17.