Security update: We discovered CVE-2026-54405 (CVSS 7.5). Ubiquiti has patched it—update UniFi Network to 10.4.57 or later.

Read the advisory

UniFi SSH commands: cheat sheet for APs, switches and gateways

These are the UniFi SSH commands you'll use most. set-inform points a device at a controller. upgrade installs firmware from a link. cat /var/log/messages shows the device log.

Every command here comes from Ubiquiti's help center, except the ones in the last table. Ubiquiti doesn't document those.

Ubiquiti's own advice is to use SSH only when its support team asks you to, because a wrong command can break a device. The login banner on the device warns about the same risk. It also says that using SSH to change a device outside its normal scope voids the warranty.

Quick reference

Command What it does Runs on
set-inform http://<host>:8080/inform Points the device at a UniFi controller for adoption APs, switches
upgrade <firmware-url> Downloads and installs firmware APs, switches, USG
syswrapper.sh upgrade2 & Installs firmware you copied to /tmp/fwupdate.bin APs, switches
ubnt-systool fwupdate <url-or-file> Installs UniFi OS firmware Consoles and gateways
cat /var/log/messages Shows the device log All UniFi devices
show tech-support Collects switch logs for support Switches, after telnet localhost and enable

To open the session first, run ssh <username>@<device-ip> from a computer on the same local network. The username is root on consoles and on gateways such as the UXG. On access points and switches it's the random device SSH username your UniFi Network application created. Our guide on how to SSH into UniFi APs, switches and consoles walks through each device type.

set-inform: adopt a device to a remote controller

set-inform tells a UniFi device where its controller is. You need it when the device can't find the controller on its own, for example with a cloud-hosted controller or across VLANs.

bash
set-inform http://<ip-or-hostname>:8080/inform

Ubiquiti's steps for a new network, from its Remote Adoption (Layer 3) article:

  1. Reset the device to factory defaults.
  2. Connect a laptop to the same network with a cable.
  3. SSH into the device and run set-inform.
  4. Open Site Manager or the UniFi mobile app and adopt the device that shows as ready to adopt.

Some details that matter:

  • Ubiquiti writes the URL with http:// and port 8080. The device and controller need open TCP 8080 between them.
  • On Official UniFi Hosting, the dashboard has a Copy Inform URL button.
  • Ubiquiti's Device Adoption article says you may need to run the command again after the device appears in UniFi.
  • Access point firmware 6.6.36 fixed a bug where an AP went offline after a management subnet change until set-inform was run again.

Our set-inform guide covers the full adoption flow with screenshots.

Firmware upgrades over SSH

Ubiquiti calls SSH updating "not an officially supported process" and says to use it only at the request of its support team. It's meant for cases where the normal update fails, or a device can't be adopted because its firmware is too old. Copy firmware links from community.ui.com/releases.

The commands below come from Ubiquiti's Advanced Updating Techniques article.

Access points and switches

With internet access on the device:

bash
upgrade https://dl.ui.com/unifi/firmware/<model>/<version>/<file>.bin

Without internet access, copy the file from your computer first, then install it:

bash
scp firmwarefile.bin <user>@<device-ip>:/tmp/fwupdate.bin
syswrapper.sh upgrade2 &

For the USW-Multi firmware image, run fwutil -p /tmp/fwupdate.bin before syswrapper.sh upgrade2 &.

Consoles and gateways

bash
ubnt-systool fwupdate <firmware-url>
ubnt-systool fwupdate /tmp/fwupdate.bin

The first line downloads the firmware. The second installs a file you copied to /tmp with scp. A UDM, UDM Pro or UXG-Pro still on version 1.x uses ubnt-upgrade instead.

UniFi Security Gateway (USG)

With internet, the USG takes the same upgrade <firmware-url> command. Without it, rename the file to upgrade.tar, copy it to /home/<user>/ and run:

bash
sudo syswrapper.sh upgrade upgrade.tar

Logs and packet captures

These come from Ubiquiti's Advanced Logging Information article. Most of the same data is in the support file, which you can download from the device panel without SSH.

Command What it shows Runs on
cat /var/log/messages The general device log All UniFi devices
tail -f /var/log/messages The same log, live All UniFi devices
cat /var/log/freeradius/radius.log RADIUS logs UniFi gateways
cat /var/log/dnsmasq.log DHCP and DNS logs UniFi gateways
cat /var/log/suricata/suricata.log IPS/IDS detections UniFi gateways
tcpdump -i <interface> Live traffic on one interface Access points
tcpdump -npi <interface> Live traffic on one interface Gateways

UniFi switch and USG commands

On UniFi switches, Ubiquiti collects extra logs for support with these three commands:

bash
telnet localhost
enable
show tech-support

The legacy USG has its own commands:

Command What it shows
show log The general log
show vpn log VPN logs
show ip route | grep vti Which route uses a VPN tunnel interface
show tech-support | no-more The full support output

For more on the USG, see our guide to SSH on the UniFi Security Gateway.

Commands Ubiquiti doesn't document

You'll find these in forum threads and older guides. None of them appears in Ubiquiti's current help center, so treat them as unofficial. Each has a documented alternative.

Command What users report it does Documented alternative
info Prints the model, firmware version, IP address and inform status The device panel in UniFi Network
set-default Resets the device to factory defaults Forget the device in UniFi Network, or hold the reset button
syswrapper.sh restore-default The same reset, on older firmware As above
reboot Restarts the device (a standard Linux command) Restart in the device panel

Ubiquiti says Forget in UniFi Network removes the device and restores it to factory defaults. The reset button does the same after 5 to 10 seconds, depending on the device (How to Reset UniFi Devices to Factory Defaults).

After a reset, the device's SSH login goes back to the factory default. Our post on the UniFi SSH password lists the defaults per device type.

Frequently asked questions

Is the info command official?

No. Many guides use info, but Ubiquiti doesn't document it. The device panel in UniFi Network shows the same model, firmware and IP details.

Can I run these commands without SSH?

On devices UniFi Network already manages, yes. It has a Debug console for each device: open the device, go to its Settings and select Debug at the bottom. Ubiquiti recommends it over SSH. It does need a working UniFi OS, and Ubiquiti advises against pasting long commands into it. For a device that isn't adopted yet, Ubiquiti's set-inform steps use SSH.

Should set-inform use http or https?

Use http. Ubiquiti's instructions only use http:// with port 8080. The same URL works for DHCP option 43 and DNS-based adoption.

Is it safe to upgrade firmware over SSH?

Only as a last resort. Ubiquiti documents the SSH upgrade commands, but calls the process unsupported outside a support request. The device login banner warns that using SSH to change a device outside its normal scope voids the warranty. If you can update through the interface, do that.

Final thoughts

Most UniFi SSH work comes down to three jobs: pointing a device at its controller, forcing a firmware update and pulling logs for support. Ubiquiti documents commands for all three. For anything else, the device panel or the Debug console is the safer route.

Running a controller for your own network and reaching devices by SSH is perfectly reasonable. For client networks, the controller those devices report to has to stay online, updated and backed up. We run UniFi OS Server as a managed service with daily backups and tested updates on paid plans, and the Debug console works on it the same way.