This walkthrough first went up in 2019, and a lot has changed since. Ubiquiti has discontinued the USG line entirely and now points people toward the UXG gateways for new deployments. The firmware download link and version numbers referenced below are from that era, so the latest firmware from Ubiquiti may no longer live at the same address and the specific versions are outdated. The recovery method itself still works to bring a dead USG-3P back for spare or low-stakes use, but treat the exact links and version numbers as a starting point, not gospel. If you’re standing up a gateway today, plan around a current, supported model.
A client calls. Nobody in the office can get online. You pull up your UniFi controller and there it is. Their Unifi USG is sitting offline. You walk them through a reboot. Then another. Nothing. So you send a tech on site, and they find the status ring glowing white with the link lights misbehaving no matter what’s plugged in. A couple more reboots later, the gateway is still dead.
At that point most people trash the unit or start an RMA. But a bricked USG-3P usually isn’t dead at all. The gateway runs its operating system off a small USB
drive inside the case, and when that drive’s image gets corrupted, the device won’t boot. A brand new USG ran about $129, so a bricked one was never the end of the world. Re-flash that drive with a clean image and the “dead” gateway comes right back to life. Here’s exactly how to do it.
First, get the client back online
Before you do anything clever, take care of the customer. Swap the bricked gateway for a spare from your inventory so they’re back on the internet, then take the dead unit back to your bench. Recovery is a workshop job, not a job site job. You don’t want a client watching the clock while you flash a USB drive.
What you’ll need
The whole process takes around 30 minutes once you have your parts together. You’ll want:
- A small Phillips head screwdriver
- A computer with a USB port (Windows, macOS, or Linux all work)
- The correct USG firmware image from Ubiquiti
- An image writer such as Win32 Disk Imager on Windows, or Disk Utility /
ddon macOS and Linux - A network connection with DHCP for the final firmware upgrade
Step 1: Open the case and pull the USB drive
Flip the gateway over and peel off the rubber feet covering the screws on the bottom. Remove the screws, then lift the top of the case off. Inside, on the circuit board, you’ll see a small USB drive. Slide it out. It may take a little force.
Step 2: Plug the drive into your computer
Insert the USB drive into your computer. Windows will almost certainly complain that it can’t read the drive and offer to format it. Ignore that. Do not format it. Just close the error and note the drive letter Windows assigned, because you’ll need it when you flash the image.

Step 3: Download the firmware image from Ubiquiti
Grab the matching USG firmware image directly from Ubiquiti’s download site. The recovery image is an older base firmware (the unzipped file is named something like USG-4_2_0-shipped.img), which is expected. You’ll update it to the current version after the gateway boots. Unzip the download to a location on your computer so you end up with the raw .img file ready to write.
The recovery image gets the gateway booting again on a known good base. The newer firmware won’t adopt cleanly onto a freshly flashed drive, so the order matters. Flash the base image first, boot, then upgrade.
Step 4: Flash the image to the USB drive
Install and open your image writer. In Win32 Disk Imager, select the image file you downloaded and extracted, then choose the device, the same drive letter you noted earlier. Double-check that drive letter. Writing to the wrong drive will overwrite the wrong device, so confirm it before you click Write.
Click Write and let it run. On a typical machine this takes around seven minutes. When it finishes, you may see that “can’t read the drive” error again. Ignore it again, then safely remove the drive.

Step 5: Reassemble the gateway
Re-insert the USB drive into the port on the USG circuit board. Put the top of the case back on, replace the screws, and press the rubber feet back into place. The feet are optional but recommended. They keep the unit from sliding around and cover the screws.
Step 6: Connect, forget, and adopt
Now bring the gateway back to life on your network. Plug the WAN port into a connection that hands out DHCP, and connect your computer to the LAN port so you can reach the device. Power it up. After a few minutes the status light cycles from flashing white to solid, which means it has booted and taken its default IP on the LAN.
In your UniFi controller, forget the old gateway first. One quirk worth knowing: when the original was written, trying to adopt the device before forgetting the previous entry failed because the controller version was too new to adopt the old firmware running on the freshly flashed USG. Forget the old entry, then handle the adoption after you upgrade the firmware in the next step.
Step 7: Upgrade the firmware
The gateway is now running that older 4.2 base firmware, so update it. SSH into the USG using the default credentials (username ubnt, password ubnt), then run the upgrade command from the CLI:
upgrade https://dl.ubnt.com/unifi/firmware/UGW3/4.4.57.5578372/UGW3.v4.4.57.5578372.tar
Hit enter and give it time. After about five minutes the USG reboots with the firmware installed, and you can adopt it into the controller. You’re left with a fully recovered gateway ready to go back into your spares pile.
Total time from a dead unit to a working one is usually under 30 minutes. Not bad for a gateway you were about to throw away.
The bigger lesson for your network
A bricked gateway is an annoyance when you have a spare on the shelf. It’s a crisis when you don’t, and the client is offline with no clear timeline. That’s the real takeaway here. The fix is straightforward, but the reason it stays cheap and calm is preparation: a spare in inventory, a documented recovery process, and someone who has done it before.
That’s the difference between break-fix scrambling and a managed approach. When your network gear is monitored, documented, and backed by ready spares, an outage like this becomes a quiet swap instead of a fire drill. If you’d rather not be the one cracking open a gateway at 9pm, that’s exactly the kind of work a good managed IT partner handles for you.
Tired of network gear failing at the worst possible moment? We monitor, document, and keep spares on hand so an outage stays a non-event. No pressure, no obligation, just a straight look at your setup.
Frequently asked questions
Last updated: June 2, 2026
