CVE-2025-27212
9.8Ubiquiti Inc · UniFi Access
Improper input validation in UniFi Access devices allows an unauthenticated remote attacker to perform command injection via the management network.
Executive summary
A critical command injection vulnerability in Ubiquiti UniFi Access devices allows unauthenticated attackers to execute arbitrary code.
Vulnerability
This vulnerability involves improper input validation that permits command injection. It is accessible to unauthenticated attackers with network access to the management interface.
Business impact
A successful exploit allows for full remote code execution, granting an attacker complete control over the affected hardware. Given the CVSS score of 9.8, this poses a severe risk of unauthorized access to physical security infrastructure and sensitive network segments.
Remediation
Immediate Action: Apply the latest firmware updates provided by Ubiquiti via the UniFi management console immediately.
Proactive Monitoring: Monitor management network traffic for suspicious command patterns or unexpected connections to UniFi Access devices.
Compensating Controls: Restrict access to the UniFi Access management network to trusted administrative IP addresses only, using VLAN segmentation or firewall rules.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The severity of this flaw necessitates immediate attention. Administrators must ensure all affected UniFi Access devices are updated to the latest firmware versions to mitigate the risk of remote code execution.