Ubiquiti’s UniFi lineup built its entire reputation on one promise: enterprise-grade networking gear that a single IT person (or a broadcast engineer moonlighting as network admin) can manage from a slick app, from anywhere, without a six-figure Cisco support contract. That promise is also, this week, the reason roughly 100,000 UniFi devices are sitting on the open internet with a target on their backs.

On July 8, Ubiquiti shipped Security Advisory Bulletin 066, patching seven critical flaws spread across UniFi Connect, Talk, Access, Protect, and OS. The headline item, CVE-2026-50746, scores a flawless 10.0 on the CVSS scale — the vulnerability equivalent of a perfect judges’ score, except the routine is “unauthenticated attacker sends one crafted request and gets arbitrary command execution on your building’s access control and lighting controller.” No login required, no user interaction. Six more flaws in the same bulletin sit in the 9.0–9.9 range, touching UniFi Talk’s phone system, UniFi Access’s door controllers, and UniFi Protect’s video feeds via an SSRF chain.

Point the controller at the world, manage it from your phone, never think about it again — until someone else does the thinking for you.

The kicker: threat intel firm Censys puts roughly 100,000 UniFi OS endpoints reachable straight from the public internet right now — which is precisely the deployment pattern UniFi’s whole pitch encourages. Ubiquiti says there’s no evidence these seven are being actively exploited yet, but a different trio of UniFi OS bugs was already flagged by CISA as weaponized in real-world attacks just last month. And Ubiquiti gear has history here: Russian state-sponsored hackers ran the MooBot botnet off compromised Ubiquiti EdgeOS routers for years before a 2024 law enforcement takedown finally killed it.

None of this makes UniFi bad gear. It makes it exactly what it’s always been: brilliant hardware wrapped in a management philosophy that assumes the internet is friendlier than it is. If you’re running UniFi Connect, Access, Protect, or Talk — and if you’ve got a studio, small office, or rental property with a Ubiquiti controller in a closet somewhere, you probably are — patch to the fixed builds today (Connect 3.4.20, Talk 5.2.2, Access 4.2.29, Protect 7.1.83, OS 5.1.19) and then ask the harder question: why does that controller have a public IP at all?

For most small deployments, the honest answer is: it doesn’t need one. The controller should sit behind a private, authenticated access layer that only your team can reach — not the entire internet plus whoever’s scanning Shodan and Censys this week.

Worth trying

The fix here isn't a firewall rule you'll forget about — it's putting management interfaces behind a proper private network layer instead of a raw public IP. NordLayer (Nord Security's business VPN / Zero Trust access product) is built for exactly this: your controller stays reachable to your team and invisible to everyone else scanning the internet.

ชื่อเสียงทั้งหมดของ UniFi จาก Ubiquiti สร้างขึ้นจากคำมั่นสัญญาเดียว คืออุปกรณ์เครือข่ายระดับองค์กรที่คนไอทีคนเดียว (หรือวิศวกรออกอากาศที่รับหน้าที่ดูแลเครือข่ายไปด้วย) สามารถจัดการได้จากแอปสวย ๆ จากที่ไหนก็ได้ โดยไม่ต้องเสียค่าซัพพอร์ต Cisco หลักแสน คำมั่นสัญญานั้นเองก็เป็นเหตุผลที่สัปดาห์นี้อุปกรณ์ UniFi ราว 100,000 เครื่องกำลังเปิดโล่งอยู่บนอินเทอร์เน็ตพร้อมเป็นเป้าโจมตี

เมื่อวันที่ 8 กรกฎาคม Ubiquiti ออก Security Advisory Bulletin 066 แพตช์ช่องโหว่ระดับวิกฤต 7 รายการ ครอบคลุม UniFi Connect, Talk, Access, Protect และ OS ตัวเด่นคือ CVE-2026-50746 ที่ได้คะแนนเต็ม 10.0 บนสเกล CVSS ซึ่งเทียบเท่ากับคะแนนเต็มจากกรรมการ เพียงแต่ท่าที่แสดงคือ “ผู้โจมตีที่ไม่ต้องล็อกอินส่งคำขอที่สร้างขึ้นมาเพียงครั้งเดียว ก็สามารถรันคำสั่งใด ๆ บนตัวควบคุมระบบควบคุมการเข้าออกและระบบไฟส่องสว่างของอาคารได้ทันที” ไม่ต้องล็อกอิน ไม่ต้องให้ผู้ใช้ทำอะไรเลย ช่องโหว่อีก 6 รายการในบูลเลตินเดียวกันอยู่ในช่วง 9.0–9.9 กระทบทั้งระบบโทรศัพท์ของ UniFi Talk ตัวควบคุมประตูของ UniFi Access และฟีดวิดีโอของ UniFi Protect ผ่านช่องโหว่ SSRF

ชี้ตัวควบคุมออกสู่โลกภายนอก จัดการมันผ่านมือถือ แล้วไม่ต้องคิดถึงมันอีกเลย — จนกว่าจะมีคนอื่นคิดแทนคุณ

ประเด็นสำคัญคือ บริษัทข่าวกรองภัยคุกคาม Censys ระบุว่าตอนนี้มีเอนด์พอยต์ UniFi OS ราว 100,000 เครื่องที่เข้าถึงได้โดยตรงจากอินเทอร์เน็ตสาธารณะ ซึ่งเป็นรูปแบบการติดตั้งที่แนวทางการขายของ UniFi สนับสนุนพอดี Ubiquiti ระบุว่ายังไม่มีหลักฐานว่าช่องโหว่ทั้ง 7 นี้ถูกใช้โจมตีจริง แต่ก่อนหน้านี้เมื่อเดือนที่แล้ว CISA เคยแจ้งเตือนว่าช่องโหว่อีกชุดหนึ่งใน UniFi OS ถูกนำไปใช้โจมตีจริงแล้ว และอุปกรณ์ Ubiquiti ก็มีประวัติในเรื่องนี้ แฮกเกอร์ที่ได้รับการสนับสนุนจากรัฐบาลรัสเซียเคยใช้เราเตอร์ Ubiquiti EdgeOS ที่ถูกแฮ็กเพื่อรันบอตเน็ต MooBot อยู่หลายปี ก่อนจะถูกปราบปรามโดยหน่วยงานบังคับใช้กฎหมายในปี 2024

เรื่องนี้ไม่ได้แปลว่า UniFi เป็นอุปกรณ์ที่แย่ มันแค่เป็นสิ่งที่มันเป็นมาตลอด คือฮาร์ดแวร์ที่ยอดเยี่ยมห่อหุ้มด้วยแนวคิดการจัดการที่สมมติว่าอินเทอร์เน็ตเป็นมิตรมากกว่าความเป็นจริง ถ้าคุณใช้งาน UniFi Connect, Access, Protect หรือ Talk อยู่ — และถ้าคุณมีสตูดิโอ ออฟฟิศเล็ก ๆ หรือบ้านเช่าที่มีตัวควบคุม Ubiquiti ซ่อนอยู่ในตู้สักที่หนึ่ง คุณก็น่าจะใช้อยู่ — ให้อัปเดตเป็นเวอร์ชันที่แก้ไขแล้ววันนี้เลย (Connect 3.4.20, Talk 5.2.2, Access 4.2.29, Protect 7.1.83, OS 5.1.19) แล้วค่อยถามคำถามที่ยากกว่า คือทำไมตัวควบคุมนั้นถึงต้องมี public IP ตั้งแต่แรก

สำหรับการติดตั้งขนาดเล็กส่วนใหญ่ คำตอบที่ตรงไปตรงมาคือ ไม่จำเป็นเลย ตัวควบคุมควรอยู่หลังชั้นการเข้าถึงแบบส่วนตัวที่ต้องยืนยันตัวตน ซึ่งมีแค่ทีมของคุณเท่านั้นที่เข้าถึงได้ ไม่ใช่อินเทอร์เน็ตทั้งหมดบวกกับใครก็ตามที่กำลังสแกน Shodan และ Censys อยู่สัปดาห์นี้

น่าลองใช้

ทางแก้ตรงนี้ไม่ใช่กฎไฟร์วอลล์ที่คุณจะลืมไปในที่สุด แต่คือการเอาอินเทอร์เฟซการจัดการไปไว้หลังชั้นเครือข่ายส่วนตัวที่เหมาะสม แทนที่จะเปิด public IP โล่ง ๆ NordLayer (ผลิตภัณฑ์ VPN / Zero Trust สำหรับธุรกิจของ Nord Security) ถูกสร้างมาเพื่อสิ่งนี้โดยเฉพาะ ตัวควบคุมของคุณยังเข้าถึงได้สำหรับทีม แต่มองไม่เห็นสำหรับคนอื่นที่กำลังสแกนอินเทอร์เน็ตอยู่

Sources:แหล่งข้อมูล: The Hacker News, Ubiquiti Security Advisory Bulletin 066, Tech Times, BleepingComputer

Disclosure: this piece may contain affiliate links. If you buy through one, The Daily Take may earn a commission at no extra cost to you. We only link tools we'd genuinely recommend. Full policy on the about page. คำชี้แจง: บทความนี้อาจมีลิงก์พันธมิตร หากคุณซื้อผ่านลิงก์เหล่านี้ The Daily Take อาจได้รับค่าคอมมิชชันโดยไม่มีค่าใช้จ่ายเพิ่มเติมสำหรับคุณ เราแนะนำเฉพาะเครื่องมือที่เราเชื่อมั่นจริง ๆ อ่านนโยบายฉบับเต็มได้ที่หน้าเกี่ยวกับเรา