CVE-2025-24292
BaseFortify
Publication date: 2025-06-29
Last updated on: 2025-06-30
Assigner: HackerOne
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is caused by a misconfigured query in UniFi Network (version 9.1.120 and earlier) that allows users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device's MAC address through 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.
How can this vulnerability impact me? :
An attacker could potentially gain unauthorized access to Enterprise WiFi or VPN services by spoofing a device's MAC address, bypassing normal authentication mechanisms. This could lead to unauthorized network access and potential exposure of sensitive network resources.