PT-2026-2073 · Ubiquiti · Ubb+3

Published

2026-01-08

·

Updated

2026-05-19

·

CVE-2026-21638

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UBB-XG versions 1.2.2 and earlier UDB-Pro/UDB-Pro-Sector versions 1.4.1 and earlier UBB versions 3.1.5 and earlier
Description A malicious actor within Wi-Fi range of the affected product could exploit a flaw in the airMAX Wireless Protocol to achieve remote code execution (RCE) on the affected product.
Recommendations Update UBB-XG to version 1.2.3 or later. Update UDB-Pro/UDB-Pro-Sector to version 1.4.2 or later. Update UBB to version 3.1.7 or later.

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-21638

Affected Products

Ubb
Ubb-Xg
Udb-Pro
Udb-Pro-Sector