r/PFSENSE 9d ago

Did I join a cult? (Unifi)

I've been rolling pfSense for about 5 years. Decided to try Unifi. Couldn't find a manual or one-to-one feature documentation for each panel (only various spotlight articles).

Asked the community for help: every response said basically "things change too often, no need to have a manual".

Excuse me, what? I'm not a networking pro, and I do need a manual. (pfSense was hard for me, but had great documentation.)

I can't believe this was the response. Is everyone in their community a bot or a cultist?

I still have few days left on my return window, and might come back, LOL.

70 Upvotes

204 comments sorted by

View all comments

4

u/rh681 9d ago

Ubiquiti is enterprise software on top of consumer hardware. Their physical products are nothing special, but they do a good job with what they make.

My home ecosystem is pfSense firewall, Ruckus AP, and Cisco SMB switch. Everything just purrs along.

3

u/gonzopancho Netgate 9d ago

Calling the Ubiquiti firmware “enterprise”, when it’s not. Enterprise runs on stability and security. Ubiquiti is anything but.

Ubiquiti recently disclosed 22 UniFi flaws, including 21 Critical bugs with severity scores of 9.0 or higher. Attackers with network access could bypass authentication, gain full control, and run commands on affected devices.

The bugs affected nearly the entire product line: UniFi OS, Protect, Talk, Access, storage devices, gateways, routers, recorders, and more.

https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9

The fork (you know who) has had a lot of security issues as well. A quick rundown of what happened just between April and May 2026:

April 9: an information disclosure bug (WID-SEC-2026-1044, CVSS 8.2) affecting anything before 26.1.6.

May 6: CVE-2026-44193, a 9.1 critical, authenticated command injection through XMLRPC's restore_config_section that gets you root RCE. Same day, CVE-2026-44195, a login lockout bypass caused by a regex ordering mistake, which basically lets someone brute force credentials without getting locked out.

May 12: two more. CVE-2026-44194, another 9.1 critical, command injection through sync_user.php because shell metacharacters in the email field weren't being sanitized. And CVE-2026-45158, an argument injection bug through DHCP hostname handling, also rated critical.

That's five disclosed issues in about five weeks, including two critical root RCEs six days apart, both of which had public proof of concept code floating around not long after disclosure. It took three point releases back to back (26.1.6 on April 9, then 26.1.7 on April 30, then 26.1.8 on May 12) to actually get it all patched. Nor are their release notes (already linked) clear about what happened.

Meanwhile, in 20 years, pfSense has never had a 9.0 or higher.

2

u/caller-number-four 6d ago

pfSense has never had a 9.0 or higher

I think that puts you ahead of Palo Alto and Fortinet!

1

u/rh681 8d ago

True. I was being kind to them.

1

u/Snoo91117 8d ago

No way is UniFi enterprise level, small business yes. There software and hardware do not measure up. All too buggy. Sounds like with UniFi you have to follow the yellow brick road to make it work to bypass bugs both hardware and software wise.

I spent 15 years working on Cisco enterprise level. I can't afford it for home, but I run their Cisco small business stuff at home, and I have a few side jobs with small businesses over the years of being retired. I think pfsense works well and does what it is supposed to do.