CVE-2026-77549

Summary

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Affected Software

VendorProductVersion RangeStatus
Ubiquiti IncUniFi OS Server0 < 5.1.37affected
Ubiquiti IncCloud Keys0 < 5.1.31affected
Ubiquiti IncNetwork Video Recorders0 < 5.1.31affected
Ubiquiti IncEnterprise Network Video Recorders0 < 5.1.31affected
Ubiquiti IncEnterprise Network Attached Storage0 < 5.1.31affected
Ubiquiti IncDream Machines0 < 5.1.31affected
Ubiquiti IncEnterprise Firewall Core0 < 5.1.31affected
Ubiquiti IncDream Routers0 < 5.1.31affected
Ubiquiti IncEnterprise Fortress Gateway0 < 5.1.31affected
Ubiquiti IncCloud Gateways0 < 5.1.31affected
Ubiquiti IncDream Wall0 < 5.1.31affected
Ubiquiti IncExpress 70 < 5.1.31affected
Ubiquiti IncNetwork Attached Storage0 < 5.1.32affected
Ubiquiti IncExpress0 < 4.0.17affected

Weaknesses

  • CWE-93: CWE-93 Improper neutralization of CRLF sequences ('CRLF injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References