Loading
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.
Use CWE-77, Ui vendor hub and Unifi Network Application product page to widen CVE-2024-42025 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-28365, CVE-2023-41721 and CVE-2023-32000 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.