important · Firmware — UniFi
A working exploit reproduces UniFi OS authentication bypass from an unauthenticated request.
Affects
Ubiquiti UniFi OS, the appliance platform used by Cloud Keys, Dream Machines, gateways, NVRs and UniFi OS Server.
Attacker-chosen CRLF sequences cause UniFi OS to misparse the request boundary and skip authentication.
Detail and 1 source
Public material includes a working target, packet captures, and exploit detections.
A patch is reported, but affected and fixed version tables could not be retrieved from the vendor page.