CVE-2024-27981

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device. Affected Products: UniFi Network Application (Version 8.0.28 and earlier) . Mitigation: Update UniFi Network Application to Version 8.1.113 or later.
Configurations

No configuration.

History

18 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

21 Nov 2024, 09:05

Type Values Removed Values Added
References () https://community.ui.com/releases/Security-Advisory-Bulletin-038-038/9d13fead-47de-4372-b2c1-745b8d6b0399 - () https://community.ui.com/releases/Security-Advisory-Bulletin-038-038/9d13fead-47de-4372-b2c1-745b8d6b0399 -

04 Apr 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-04 23:15

Updated : 2025-03-18 21:15


NVD link : CVE-2024-27981

Mitre link : CVE-2024-27981

CVE.ORG link : CVE-2024-27981


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')