CVE-2026-22563
Received
Received - Intake
Command Injection via Improper Input Validation in UniFi Play Devices
Publication date: 2026-04-13
Last updated on: 2026-04-13
Assigner: HackerOne
Description
Description
A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network.
Affected Products:
UniFi Play PowerAmp (Version 1.0.35 and earlier)β¨
UniFi Play Audio PortΒ (Version 1.0.24 and earlier)β¨
Mitigation:
Update UniFi Play PowerAmp to Version 1.0.38 or laterβ¨
Update UniFi Play Audio PortΒ to Version 1.1.9 or later
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ubiquiti | unifi_play_poweramp | to 1.0.36 (exc) |
| ubiquiti | unifi_play_audio_port | to 1.0.25 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |