Critical ubiquiti remote root vuln

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

PigLover

Moderator
Jan 26, 2011
3,186
1,545
113
This seems to be pretty bad behavior by UBNT - not updating to modern tool stacks, allowing a backlog/bottleneck to form in their review of security reports, slow to fix, etc.

However - needs a small clarification: this applies to UBNT Routing and firewall products - not to Unifi APs/Switchs or IOT devices like mFI. So if you have Unifi APs or switches - probably the largest use case for readers here - you don't need to panic (yet - given the red flags noted above there may still be issues lurking here too).
 
  • Like
Reactions: Geran

Tom S

Member
Jan 31, 2017
42
20
8
38
Chris Buechler wrote a good synopsis of the issue here: Security flaws disclosed affecting multiple Ubiquiti products • r/Ubiquiti

As others have mentioned, UniFi and UniFi Video devices are not affected by this vulnerability. I'm part of the UniFi team and I can assure you we take security very seriously. HackerOne reports are evaluated, triaged, and addressed very quickly by the UniFi teams. We also stay on top of vulnerabilities as they are announced and integrate fixes as quickly as possible.
 
Last edited:
  • Like
Reactions: Geran and wildchild

Tom S

Member
Jan 31, 2017
42
20
8
38
Welcome onboard Tom :)
Thanks pricklypunter. I'm not really here in an official capacity, but we like to remain engaged with the community. I followed STH and lurked in the STH forums long before I joined Ubiquiti. This site and the community here are good resources for gathering more perspectives on our gear and the market in general, all of which is folded back in to our product roadmaps and iterative improvements.