Ubiquiti Patches Three Critical Flaws Allowing Remote Takeover
Ubiquiti has shipped patches for three vulnerabilities rated at the highest possible severity level, each of which could be exploited remotely by attackers who have no prior access or login credentials. While the company hasn't detailed exact exploitation scenarios publicly, flaws of this severity typically allow full device compromise, letting an attacker execute code, hijack network traffic, or pivot deeper into a network.
Ubiquiti's routers, switches, and access points are widely used by small businesses, ISPs, and home-lab enthusiasts alike, making these devices an attractive target for botnets and opportunistic scanning campaigns. Given the unauthenticated, remote nature of the bugs, any exposed or unpatched device is at meaningful risk.
Admins running Ubiquiti hardware should update firmware immediately rather than waiting for a routine maintenance window.