CVE-2026-22562

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Play PowerAmp to Version 1.0.38 or later
Update UniFi Play Audio Port  to Version 1.1.9 or later
Configurations

No configuration.

History

13 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 22:16

Updated : 2026-04-30 16:14


NVD link : CVE-2026-22562

Mitre link : CVE-2026-22562

CVE.ORG link : CVE-2026-22562


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')