PT-2026-2073 · Ubiquiti · Ubb+3

CVE-2026-21638

·

Published

2026-01-08

·

Updated

2026-08-10

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UBB-XG versions 1.2.2 and earlier UDB-Pro/UDB-Pro-Sector versions 1.4.1 and earlier UBB versions 3.1.5 and earlier
Description A malicious actor within Wi-Fi range of the affected product could exploit a flaw in the airMAX Wireless Protocol to achieve remote code execution (RCE) on the affected product.
Recommendations Update UBB-XG to version 1.2.3 or later. Update UDB-Pro/UDB-Pro-Sector to version 1.4.2 or later. Update UBB to version 3.1.7 or later.

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21638

Affected Products

Ubb
Ubb-Xg
Udb-Pro
Udb-Pro-Sector