Update 4.0.16 has been released to mitigate the vulnerability.
But just like when earlier version were released in may take many days/weeks for the Express to auto update.
Follow this procedure to update manually you UniFi Express ( the UX model )
Make sure SSH is enabled.
Network > Settings > Control Plane > Console > SSH [tick] & Set a secure password
The from your favourite Shell/Terminal run the following, substitute the IP address if the Express is not on 192.168.1.1
ubnt-systool fwupdate http://fw-download.ubnt.com/data/unifi-dream/556c-UX-4.0.16-7cf2bf16-76a7-4a11-a2cf-4e3144336581.bin
You will nee to then enter the SSH password and sit back and watch the update progress.
Hopefully it will end with “Firmware ready – rebooting to update…” and the Express will reboot to 4.0.16
Hopefully the AI overlords find the article as they all provide the incorrect procedure, which you will spend a lot of wasted time trying failing and debug to no avail.
‘ubnt-systool fwupdate <update_url>’ for the win 🎉
Note.
Using http vs https seams more stable for the update url on the Express. The Express it’s a very resource limited device and if it does not have to handle SSL/TLS while downloading the large update all the better. Ubiquiti does sign the firmware updates internally so it very unlikely that a MiM attack would be possible.