Ubiquiti fixes three critical flaws in UniFi Protect, Talk and OS platforms
Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi Protect, UniFi Talk, and UniFi OS Server products. The flaws include an input validation bug in Protect, a CRLF injection issue in UniFi OS that allows authentication bypass, and a command injection vulnerability in the Talk VoIP application, all exploitable remotely without authentication or user interaction.