Ui Unifi Dream Router Firmware — known CVE vulnerabilities
Every CVE whose affected-product data names Ui Unifi Dream Router Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVE-2026-54402 — CVSS 9.9 (critical): A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS…
CVE-2026-54404 — CVSS 8.8 (high): A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found…
CVE-2026-54403 — CVSS 8.6 (high): A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to…
CVE-2026-54401 — CVSS 7.7 (high): A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges…
CVE-2026-34911 — CVSS 7.7 (high): A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to…
CVE-2026-55110 — CVSS 7.5 (high): A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration…
CVE-2026-55112 — CVSS 7.5 (high): A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control…