Skip to finding
important · Firmware — UniFi

A working exploit reproduces UniFi OS authentication bypass from an unauthenticated request.

Affects

Ubiquiti UniFi OS, the appliance platform used by Cloud Keys, Dream Machines, gateways, NVRs and UniFi OS Server.

Attacker-chosen CRLF sequences cause UniFi OS to misparse the request boundary and skip authentication.

Detail and 1 source

Public material includes a working target, packet captures, and exploit detections.

A patch is reported, but affected and fixed version tables could not be retrieved from the vendor page.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026