{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-34910",
  "revision": 1,
  "title": "Ubiquiti UniFi OS — command injection from the network",
  "summary": "Ubiquiti's UniFi operating system (OS) does not validate input properly, letting anyone who can reach the device over the network run commands on it. Exploitation in the wild has been folded into Mirai-style botnet activity.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.87468,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-06-23",
    "prerequisites": "Network access to the UniFi OS device; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Update UniFi OS per Ubiquiti Security Advisory Bulletin 064 now; keep device management off the public internet and reflash anything already in a botnet.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-34910",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-34910",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-34910",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34910",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b"
    },
    {
      "type": "exploit",
      "url": "https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/"
    }
  ],
  "published_at": "2026-05-22T02:16:34.527Z",
  "issued_at": "2026-09-23T07:33:20.707Z",
  "tags": [
    "ubiquiti",
    "unifi",
    "command-injection",
    "botnet",
    "mirai",
    "kev"
  ]
}
