CVE-2025-52663
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-31

Last updated on: 2025-12-02

Assigner: HackerOne

Description
A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Products: UniFi Talk Touch (Version 1.21.16 and earlier) UniFi Talk Touch Max (Version 2.21.22 and earlier) UniFi Talk G3 Phones (Version 3.21.26 and earlier) Mitigation: Update the UniFi Talk Touch to Version 1.21.17 or later. Update the UniFi Talk Touch Max to Version 2.21.23 or later. Update the UniFi Talk G3 Phones to Version 3.21.27 or later.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-31
Last Modified
2025-12-02
Generated
2026-05-07
AI Q&A
2025-10-31
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
ubiquiti unifi_talk_touch_max 2.21.22
ubiquiti unifi_talk_g3_phones 3.21.26
ubiquiti unifi_talk_touch 1.21.16
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-489 The product is released with debugging code still enabled or active.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in certain UniFi Talk devices where internal debugging functionality was unintentionally left enabled. An attacker who has access to the UniFi Talk management network could exploit this by invoking internal debug operations through the device API, potentially gaining unauthorized control or information.


How can this vulnerability impact me? :

If exploited, this vulnerability could allow an attacker on the management network to perform unauthorized debug operations on affected UniFi Talk devices. This could lead to unauthorized access, manipulation, or disruption of device functionality within the network.


What immediate steps should I take to mitigate this vulnerability?

Update the UniFi Talk Touch devices to Version 1.21.17 or later, UniFi Talk Touch Max devices to Version 2.21.23 or later, and UniFi Talk G3 Phones to Version 3.21.27 or later to mitigate the vulnerability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart