CVE-2026-47370: Ubiquiti Inc Efg
Critical severity, CVSS 9.9. EPSS: 1.4% chance of exploitation in the next 30 days.
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.
Affected products
- Ubiquiti Inc Efg: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Envr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Envr-Core: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Express: before 4.0.15 (fixed in 4.0.15)
- Ubiquiti Inc Express 7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Fiber: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Industrial: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Ucg-Ultra: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uck: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uck-Enterprise: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Uckp: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Beast: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-Pro-Max: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udm-SE: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udr-5g: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc UDR7: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Udw: before 5.1.15 (fixed in 5.1.15)
- Ubiquiti Inc Unas-2: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-4: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-Pro: before 5.1.16 (fixed in 5.1.16)
- Ubiquiti Inc Unas-Pro-4: before 5.1.16 (fixed in 5.1.16)
- and 7 more
Published 2026-06-12. Last modified 2026-06-17.