216.73.217.22

CVE-2025-52665

· Published 31/10/2025 00:15 · Modified 31/10/2025 14:16

Labels: CVE-2025-52665 2025-10-31CVE-2025-52665CWE-306[email protected]

Essential information

Published
31/10/2025 00:15
Modified
31/10/2025 14:16
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
unifi / unifi access cpe:2.3:a:unifi:unifi_access:3.3.22-3.4.31:*:*:*:*:*:*:*
unifi / unifi access cpe:2.3:a:unifi:unifi_access:4.0.21:*:*:*:*:*:*:*

References