Ubiquiti waarschuwt voor kritieke kwetsbaarheden in UniFi

Heb je problemen met het instellen van je netwerk, bedraad of draadloos, dan kan je hier altijd terecht!
Plaats reactie
DarkV
Elite Poster
Elite Poster
Berichten: 4645
Lid geworden op: 17 apr 2019, 11:47
Uitgedeelde bedankjes: 136 keer
Bedankt: 183 keer
Te Koop forum

Ubiquiti heeft 25 kwetsbaarheden in zijn UniFi-apps, waaronder verschillende kritieke. In het ergste geval kunnen kwaadwillenden die gebruiken om UniFi-apparaten over te nemen. Ze zijn inmiddels gepatcht; Ubiquiti raadt gebruikers aan om zo snel mogelijk te updaten.

Bron: https://tweakers.net/nieuws/249838/ubiq ... unifi.html
Abusimbal
Elite Poster
Elite Poster
Berichten: 2154
Lid geworden op: 30 okt 2004, 13:34
Uitgedeelde bedankjes: 397 keer
Bedankt: 123 keer
Recent bedankt: 2 keer
Te Koop forum

Tom Lawrence van Lawrence Systems had een maand geleden al een video gemaakt hierover.


https://www.linkedin.com/posts/computin ... 09952-Pcwa
Ubiquiti just patched five critical UniFi CVEs, three of them rated CVSS 10.0.

Headlines made it sound like the sky was falling. The reality is more useful.

Every one of those CVEs requires the same prerequisite: a malicious actor with access to the management interface. UniFi ships with that interface closed to the WAN by default. If you didn't open it, you weren't reachable. If you did open it, or accidentally exposed it through a misconfigured firewall rule, the patch released May 21st is what stands between you and a potential botnet that's already scanning the internet for unpatched consoles.

A few things worth saying clearly:

All five CVEs were found through Ubiquiti's HackerOne bug bounty program, not in the wild.

Auto-updates would have saved every person I've seen reporting a potential compromise. The window between patch release and active exploitation was about four days. That's not a window you patch manually anymore.

2FA does not help here. These are pre-authentication vulnerabilities. The strength of your login doesn't matter when the bug lets the attacker skip the login entirely. Patching is the control.

Full video walks through the bulletin, the bug bounty math, why your default UniFi deployment is probably fine, and what to do if you've exposed your management interface:
https://lnkd.in/ee-wWatT

If you have, here's how to lock the firewall down properly:
https://lnkd.in/ewVnBmxR

And the full UniFi playlist for everything else:
https://lnkd.in/gfS3D8f5
Hier zie je alle Ubiquiti releases, kan je ook togglen op "Only Security Updates"
Ze maken daarvoor Security Advisory Bulletins van
https://community.ui.com/releases

De laatste, Security Advisory Bulletin 66, is wel "extreem" ja omdat het er 25 zijn. (in 2025 waren het 10)
https://community.ui.com/releases/Secur ... 1c289b3afc

Hackers zijn dit jaar fel gefocused op CPE toestellen.
Ubiquiti: Critical vulnerabilities (including command injection, SQL injection, and path traversal) were discovered in the Ubiquiti UniFi OS, which could allow unauthenticated attackers to completely take over the device.

NETGEAR: Multiple models suffered from security flaws in 2026, including an out-of-bounds write denial-of-service flaw (CVE-2026-3088) and unauthorized access flaws affecting NETGEAR Orbi Mesh Routers and other NETGEAR Devices.

Zyxel: A critical OS command injection vulnerability (CVE-2026-13942) was identified in certain Zyxel Security Routers that allowed remote execution of operating system commands.Tenda: A hidden unauthenticated backdoor (CVE-2026-11405) was found in several.

Tenda Router families that bypassed login screens entirely.

MikroTik: A service exposure and vulnerability (CVE-2026-59108) was addressed in MikroTik RouterOS, which required urgent patching, particularly for devices with publicly exposed services.

En natuurlijk Fortinet een heel deel, als ook FortiBleed.
FortiBleed is a large-scale credential theft and exposure campaign targeting internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. The campaign compromised verified login credentials for an estimated 74,000 to 86,000 devices across 194 countries, representing roughly half of all internet-reachable Fortinet devices globally.
Telenet All-Internet (Gigabit optie)
Samsung Galaxy S25 Ultra
Ubiquiti UDM Pro
Synology DS1821+
Nvidia Shield TV console
Intel NUC 13 Extreme i7 13700K
Microsoft Surface Pro 8
Garmin Venu3
Plaats reactie

Terug naar “Netwerken en Security”