
CVE-2026-34910 Analysis: UniFi OS Mirai Botnet Chain
A CVSS 10.0 unauthenticated remote code execution vulnerability in UniFi OS is being exploited in the wild to build a Mirai botnet. Attackers are chaining an access-control bypass with a command injection flaw to take over network-edge gateways, cameras, and network video recorders. This analysis is based on vendor advisories, honeypot telemetry, and published research — we did not run the exploit hands-on. Here is what you need to know about the CVE-2026-34910 command injection and how to defend your fleet.
How This Was Researched
This assessment synthesizes public advisories and honeypot captures from May–June 2026. Primary sources: the Ubiquiti SAB-064 advisory, NVD, SentinelOne, PwnDefend, CISA KEV, and the VulnCheck network-edge report. Methodology: cross-referencing vendor patches, NVD scoring, and exploit traffic from Defused honeypots. Not covered: internal network forensics or proprietary threat intel. Last researched: August 2026.
What Is the CVE-2026-34910 Command Injection?
CVE-2026-34910 is an unauthenticated OS command injection in UniFi OS’s package-update service, rated CVSS 10.0 and actively exploited per CISA KEV. The flaw is rooted in CWE-20 (improper input validation): an attacker can inject OS commands into the pkg_name parameter when by_cmd=true is set.
The vulnerability exists in the package-update endpoint of UniFi OS. With a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, no authentication is required, and the impact is total system compromise. The vulnerable parameter is pkg_name, which is passed to a shell command without sanitization when by_cmd=true is included in the request. This gives a remote, unauthenticated attacker arbitrary command execution as root on the device.
The Exploitation Chain: From Auth Bypass to Mirai Botnet
Attackers chain an access-control bypass with a command injection flaw to reach unauthenticated remote code execution on UniFi OS. The observed in-the-wild chain combines CVE-2026-34908 — an nginx raw-vs-normalized URI mismatch that lets encoded traversal escape the public prefix — with CVE-2026-34910, which executes attacker-supplied OS commands, per PwnDefend’s honeypot telemetry.
The captured request shape from PwnDefend honeypots shows the traversal escaping the public prefix (URL-decoded for readability; on the wire the traversal is the encoded ..%2f form):
GET /api/auth/validate-sso/../../../proxy/users/api/v2/ucs/update/latest_package?pkg_name=...&by_cmd=true
The encoded ..%2f traversal bypasses nginx’s access control, reaching the internal package-update API. The pkg_name parameter then carries the injected command. The stage-1 shell loader, named “zok”, iterates 14 CPU architectures (mips, mpsl, arm, arm5, arm6, arm7, x86, arc, sh4, ppc, spc, i5, i6, m68k) to fetch a stage-2 implant. That implant, “azsxd” v2.0, is of Mirai/Gafgyt lineage and masquerades as cron.azsxd. It deletes itself while running (memory-resident) and uses wget/curl with a TFTP fallback. The staging host 185.228.26.16 serves both HTTP and TFTP (UDP 69). The infection-vector tag “unifi.exploit” proves this is one campaign within a larger multi-exploit operation, per the PwnDefend analysis. For more on botnet operations, see our residential proxy botnet takedown analysis.
Detecting Compromise and Hardening UniFi OS
Detecting a compromised UniFi OS device comes down to four signatures: the encoded traversal URI pattern in access logs, processes backed by deleted binaries, YARA matches on the azsxd implant, and unusual UDP 69/TFTP egress to staging infrastructure. Patching to the fixed versions in the SAB-064 advisory is the only reliable cure, and treat exposed pre-patch instances as compromised.
Detection:
- URI signature: Look for
..%2fcombined with/proxy/users/api/v2/ucs/update/latest_packageandby_cmd=truein access logs. - Deleted-binary process pattern: Running processes backed by deleted executables —
azsxddeletes itself from disk while running. - YARA rule for azsxd: Hunt for the implant binary’s unique strings and PE/ELF headers across your fleet.
- Monitor unusual UDP 69/TFTP egress: Botnet staging frequently uses TFTP fallback when HTTP is blocked.
Hardening:
- Patch: UniFi OS Server 5.0.8+ (vuln ≤5.0.6).
- UDM/UDM-Pro/UDM-SE/UDM-Pro-Max/EFG/UDW/UDR/UDR7/Express 7/UNVR/UNVR-Pro/UNVR-Instant/ENVR/UCG-Ultra/UCG-Max/UCG-Fiber: 5.1.12+ (vuln ≤5.0.16).
- UDR-5G/ENVR-Core/UCKP/UCK/UCK-Enterprise: 5.1.12+ (vuln ≤5.0.17).
- UNVR-G2/UNVR-G2-Pro: 5.1.12+ (vuln ≤5.1.11).
- UNAS-2/UNAS-4/UNAS-Pro/UNAS-Pro-4/UNAS-Pro-8: 5.1.10+ (vuln ≤5.1.8).
- UDM-Beast: 5.1.11+.
Treat any internet-exposed instance on an earlier build as compromised. Segment management interfaces, disable remote management where possible, and audit edge-device lifecycle — VulnCheck’s report confirms EOL devices are prime botnet targets. Review our CVE deep-dive archive for related findings and use our network scan tool to identify exposed instances.
FAQ
Below are the questions security teams most often ask about CVE-2026-34910 and its botnet exploitation. Each answer is self-contained, covering affected devices and fixed versions, compromise-detection steps, and the scope of observed in-the-wild usage, with every claim sourced inline.
What UniFi OS devices are affected by CVE-2026-34910?
All UniFi OS devices running vulnerable versions are affected, including UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max, UCG-Fiber, UDR-5G, ENVR-Core, UCKP, UCK, UCK-Enterprise, UNVR-G2, UNVR-G2-Pro, UNAS-2/4/Pro/Pro-4/Pro-8, and UDM-Beast. Fixed versions range from 5.0.8 on UniFi OS Server to 5.1.12 on most gateway and NVR families, depending on the device, per the Ubiquiti SAB-064 advisory.
How do I check if my UniFi OS device is already compromised?
Check for running processes backed by deleted executables (the azsxd implant), search access logs for the ..%2f traversal URI pattern, and look for outbound connections to staging host 185.228.26.16 over HTTP or UDP 69/TFTP. A device that was internet-exposed pre-patch should be treated as compromised and reimaged, not just patched. See our N-able N-central CVE deep-dive for similar post-compromise detection guidance.
Is CVE-2026-34910 only used to build Mirai botnets?
No — the exploit grants full root RCE, so any malware is possible, including ransomware or cryptominers. The observed in-the-wild usage is specifically the Mirai/Gafgyt IoT botnet, confirmed by PwnDefend honeypot telemetry. The CISA KEV listing confirms active exploitation, and the “unifi.exploit” tag shows attackers are running this as part of a broader multi-vulnerability campaign. For context on similar IoT threats, see our pgAdmin 4 CVE analysis.
Conclusion
CVE-2026-34910 is a critical, actively exploited flaw that turns network-edge gear into botnet soldiers. The chain is unauthenticated, and botnets feast on end-of-life devices that never get patched. Patch every UniFi OS device to the fixed versions above, treat exposed pre-patch instances as compromised, and segment management interfaces. The window between disclosure and weaponization is shrinking — your patch cadence must keep pace.