CVE-2025-27212

9.8

Ubiquiti Inc · UniFi Access

Improper input validation in UniFi Access devices allows an unauthenticated remote attacker to perform command injection via the management network.

Executive summary

A critical command injection vulnerability in Ubiquiti UniFi Access devices allows unauthenticated attackers to execute arbitrary code.

Vulnerability

This vulnerability involves improper input validation that permits command injection. It is accessible to unauthenticated attackers with network access to the management interface.

Business impact

A successful exploit allows for full remote code execution, granting an attacker complete control over the affected hardware. Given the CVSS score of 9.8, this poses a severe risk of unauthorized access to physical security infrastructure and sensitive network segments.

Remediation

Immediate Action: Apply the latest firmware updates provided by Ubiquiti via the UniFi management console immediately.

Proactive Monitoring: Monitor management network traffic for suspicious command patterns or unexpected connections to UniFi Access devices.

Compensating Controls: Restrict access to the UniFi Access management network to trusted administrative IP addresses only, using VLAN segmentation or firewall rules.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

The severity of this flaw necessitates immediate attention. Administrators must ensure all affected UniFi Access devices are updated to the latest firmware versions to mitigate the risk of remote code execution.

More Ubiquiti Inc CVEs