A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
Update Ubiquiti Inc/EFG to 5.1.12; Ubiquiti Inc/ENVR to 5.1.12; Ubiquiti Inc/ENVR-Core to 5.1.12; Ubiquiti Inc/Express 7 to 5.1.12; Ubiquiti Inc/UCG-Fiber to 5.1.12; Ubiquiti Inc/UCG-Industrial to 5.1.12; Ubiquiti Inc/UCG-Max to 5.1.12; Ubiquiti Inc/UCG-Ultra to 5.1.12; Ubiquiti Inc/UCK to 5.1.12; Ubiquiti Inc/UCK-Enterprise to 5.1.12; Ubiquiti Inc/UCKP to 5.1.12; Ubiquiti Inc/UDM to 5.1.12; Ubiquiti Inc/UDM-Beast to 5.1.11; Ubiquiti Inc/UDM-Pro to 5.1.12; Ubiquiti Inc/UDM-Pro-Max to 5.1.12; Ubiquiti Inc/UDM-SE to 5.1.12; Ubiquiti Inc/UDR to 5.1.12; Ubiquiti Inc/UDR-5G to 5.1.12; Ubiquiti Inc/UDR7 to 5.1.12; Ubiquiti Inc/UDW to 5.1.12; Ubiquiti Inc/UNAS-2 to 5.1.10; Ubiquiti Inc/UNAS-4 to 5.1.10; Ubiquiti Inc/UNAS-Pro to 5.1.10; Ubiquiti Inc/UNAS-Pro-4 to 5.1.10; Ubiquiti Inc/UNAS-Pro-8 to 5.1.10; Ubiquiti Inc/UniFi OS Server to 5.0.8; Ubiquiti Inc/UNVR to 5.1.12; Ubiquiti Inc/UNVR-G2 to 5.1.12; Ubiquiti Inc/UNVR-G2-Pro to 5.1.12; Ubiquiti Inc/UNVR-Instant to 5.1.12; Ubiquiti Inc/UNVR-Pro to 5.1.12 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCISA ADP Vulnrichment affects Ubiquiti Inc/EFG (generic), Ubiquiti Inc/ENVR (generic), Ubiquiti Inc/ENVR-Core (generic), Ubiquiti Inc/Express 7 (generic), Ubiquiti Inc/UCG-Fiber (generic), Ubiquiti Inc/UCG-Industrial (generic), Ubiquiti Inc/UCG-Max (generic), Ubiquiti Inc/UCG-Ultra (generic), Ubiquiti Inc/UCK (generic), Ubiquiti Inc/UCK-Enterprise (generic), Ubiquiti Inc/UCKP (generic), Ubiquiti Inc/UDM (generic), Ubiquiti Inc/UDM-Beast (generic), Ubiquiti Inc/UDM-Pro (generic), Ubiquiti Inc/UDM-Pro-Max (generic), Ubiquiti Inc/UDM-SE (generic), Ubiquiti Inc/UDR (generic), Ubiquiti Inc/UDR-5G (generic), Ubiquiti Inc/UDR7 (generic), Ubiquiti Inc/UDW (generic), Ubiquiti Inc/UNAS-2 (generic), Ubiquiti Inc/UNAS-4 (generic), Ubiquiti Inc/UNAS-Pro (generic), Ubiquiti Inc/UNAS-Pro-4 (generic), Ubiquiti Inc/UNAS-Pro-8 (generic), Ubiquiti Inc/UniFi OS Server (generic), Ubiquiti Inc/UNVR (generic), Ubiquiti Inc/UNVR-G2 (generic), Ubiquiti Inc/UNVR-G2-Pro (generic), Ubiquiti Inc/UNVR-Instant (generic), Ubiquiti Inc/UNVR-Pro (generic). Severity is high. A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
Update Ubiquiti Inc/EFG to 5.1.12; Ubiquiti Inc/ENVR to 5.1.12; Ubiquiti Inc/ENVR-Core to 5.1.12; Ubiquiti Inc/Express 7 to 5.1.12; Ubiquiti Inc/UCG-Fiber to 5.1.12; Ubiquiti Inc/UCG-Industrial to 5.1.12; Ubiquiti Inc/UCG-Max to 5.1.12; Ubiquiti Inc/UCG-Ultra to 5.1.12; Ubiquiti Inc/UCK to 5.1.12; Ubiquiti Inc/UCK-Enterprise to 5.1.12; Ubiquiti Inc/UCKP to 5.1.12; Ubiquiti Inc/UDM to 5.1.12; Ubiquiti Inc/UDM-Beast to 5.1.11; Ubiquiti Inc/UDM-Pro to 5.1.12; Ubiquiti Inc/UDM-Pro-Max to 5.1.12; Ubiquiti Inc/UDM-SE to 5.1.12; Ubiquiti Inc/UDR to 5.1.12; Ubiquiti Inc/UDR-5G to 5.1.12; Ubiquiti Inc/UDR7 to 5.1.12; Ubiquiti Inc/UDW to 5.1.12; Ubiquiti Inc/UNAS-2 to 5.1.10; Ubiquiti Inc/UNAS-4 to 5.1.10; Ubiquiti Inc/UNAS-Pro to 5.1.10; Ubiquiti Inc/UNAS-Pro-4 to 5.1.10; Ubiquiti Inc/UNAS-Pro-8 to 5.1.10; Ubiquiti Inc/UniFi OS Server to 5.0.8; Ubiquiti Inc/UNVR to 5.1.12; Ubiquiti Inc/UNVR-G2 to 5.1.12; Ubiquiti Inc/UNVR-G2-Pro to 5.1.12; Ubiquiti Inc/UNVR-Instant to 5.1.12; Ubiquiti Inc/UNVR-Pro to 5.1.12 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCISA ADP Vulnrichment affects Ubiquiti Inc/EFG (generic), Ubiquiti Inc/ENVR (generic), Ubiquiti Inc/ENVR-Core (generic), Ubiquiti Inc/Express 7 (generic), Ubiquiti Inc/UCG-Fiber (generic), Ubiquiti Inc/UCG-Industrial (generic), Ubiquiti Inc/UCG-Max (generic), Ubiquiti Inc/UCG-Ultra (generic), Ubiquiti Inc/UCK (generic), Ubiquiti Inc/UCK-Enterprise (generic), Ubiquiti Inc/UCKP (generic), Ubiquiti Inc/UDM (generic), Ubiquiti Inc/UDM-Beast (generic), Ubiquiti Inc/UDM-Pro (generic), Ubiquiti Inc/UDM-Pro-Max (generic), Ubiquiti Inc/UDM-SE (generic), Ubiquiti Inc/UDR (generic), Ubiquiti Inc/UDR-5G (generic), Ubiquiti Inc/UDR7 (generic), Ubiquiti Inc/UDW (generic), Ubiquiti Inc/UNAS-2 (generic), Ubiquiti Inc/UNAS-4 (generic), Ubiquiti Inc/UNAS-Pro (generic), Ubiquiti Inc/UNAS-Pro-4 (generic), Ubiquiti Inc/UNAS-Pro-8 (generic), Ubiquiti Inc/UniFi OS Server (generic), Ubiquiti Inc/UNVR (generic), Ubiquiti Inc/UNVR-G2 (generic), Ubiquiti Inc/UNVR-G2-Pro (generic), Ubiquiti Inc/UNVR-Instant (generic), Ubiquiti Inc/UNVR-Pro (generic). Severity is high. A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Ubiquiti Inc/EFGgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/ENVRgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/ENVR-Coregeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/Express 7generic | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Fibergeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Industrialgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Maxgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Ultrageneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCKgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCK-Enterprisegeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCKPgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDMgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDM-Beastgeneric | >=0 <5.1.11 | 5.1.11 |
| Ubiquiti Inc/UDM-Progeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDM-Pro-Maxgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDM-SEgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDRgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDR-5Ggeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDR7generic | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDWgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNAS-2generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-4generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-Progeneric | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-Pro-4generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-Pro-8generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UniFi OS Servergeneric | >=0 <5.0.8 | 5.0.8 |
| Ubiquiti Inc/UNVRgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-G2generic | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-G2-Progeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-Instantgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-Progeneric | >=0 <5.1.12 | 5.1.12 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardAI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Ubiquiti Inc/EFGgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/ENVRgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/ENVR-Coregeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/Express 7generic | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Fibergeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Industrialgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Maxgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCG-Ultrageneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCKgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCK-Enterprisegeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UCKPgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDMgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDM-Beastgeneric | >=0 <5.1.11 | 5.1.11 |
| Ubiquiti Inc/UDM-Progeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDM-Pro-Maxgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDM-SEgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDRgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDR-5Ggeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDR7generic | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UDWgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNAS-2generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-4generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-Progeneric | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-Pro-4generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UNAS-Pro-8generic | >=0 <5.1.10 | 5.1.10 |
| Ubiquiti Inc/UniFi OS Servergeneric | >=0 <5.0.8 | 5.0.8 |
| Ubiquiti Inc/UNVRgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-G2generic | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-G2-Progeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-Instantgeneric | >=0 <5.1.12 | 5.1.12 |
| Ubiquiti Inc/UNVR-Progeneric | >=0 <5.1.12 | 5.1.12 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard