Ubiquiti

Ubiquiti

Top 1K site
Bounty Swag

Program Details

Handle
ui
Managed
Yes

Response Metrics

Response Time
3 days
Bounty Time
127 days
Resolution Time
1241 days
Response Efficiency
99%

Scope (50 targets)

web: 24 mobile: 4 other: 22

Bounty splitting: No

In Scope

  • UniFi OS Server other bounty-eligible
  • *.ubnt.com web bounty-eligible
  • *.ui.com web bounty-eligible
  • *.uisp.com web bounty-eligible
  • AmpliFi other bounty-eligible
  • Cloudkey other bounty-eligible
  • EdgeMAX other bounty-eligible
  • UCRM other bounty-eligible
  • UFiber other bounty-eligible
  • UID other bounty-eligible
  • UISP other bounty-eligible
  • UNMS other bounty-eligible
  • UniFi other bounty-eligible
  • UniFi Access other bounty-eligible
  • UniFi Cloud other bounty-eligible
  • UniFi Connect other bounty-eligible
  • UniFi Gateways (UDM, UXG, USG) other bounty-eligible
  • UniFi LED other bounty-eligible
  • UniFi Network Application other bounty-eligible
  • UniFi Protect other bounty-eligible
  • and 30 more targets

Out of Scope

*.go.ubnt.com, AirControl, UniFi Talk Conference Speaker - UT-Conference , UniFi Video, UniFi Video Cloud, UniFi Video Server, UniFi Voip, com.ubnt.mpower, com.ubnt.unifi.edu, com.ubnt.unifivideo, forum-es.ui.com, forum-pt.ui.com, mFi, security.community.ui.com

Known Exploited Vulnerabilities 1CVE

  • CVE-2010-5330AirOSApr 15, 202242.8% EPSS

    Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.