Summary
Ubiquiti has patched 22 vulnerabilities across its UniFi product line, including three CVSS 10.0 flaws that allow unauthenticated remote command execution and authentication bypass. The update addresses critical flaws in UniFi OS, Protect, Talk, and Network applications, impacting devices like Dream Machines and Network Video Recorders.
Take Action:
If you use Ubiquiti UniFi gear (Protect, Talk, Access, Network, Connect, UniFi OS consoles, or the UID Enterprise Agent), first make sure these devices and their management consoles are isolated from the internet and reachable only from your trusted internal network or VPN. Then update everything to the fixed versions listed in Ubiquiti's Bulletin 067 as soon as possible. There is a huge number of critical severity issues that will be exploited.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)