CVE-2025-52665
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-31
Last updated on: 2025-11-12
Assigner: HackerOne
Description
Description
A malicious actor with access to the management network could exploit a misconfiguration in UniFiβs door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.Β
Affected Products:
UniFi Access Application (Version 3.3.22 through 3.4.31). β¨
Mitigation:
Update your UniFi Access Application to Version 4.0.21 or later.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ui | unifi_access | From 3.3.22 (inc) to 4.0.21 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |