CVE-2025-27214

9.8

Ubiquiti Inc · UniFi Connect EV Station Pro

A missing authentication vulnerability in the UniFi Connect EV Station Pro allows unauthorized actors with physical or adjacent access to perform a factory reset.

Executive summary

A critical missing authentication vulnerability in the UniFi Connect EV Station Pro could allow an unauthorized actor to perform a factory reset, resulting in a complete loss of device configuration.

Vulnerability

This vulnerability involves a missing capability check for a critical function, allowing an attacker with physical or adjacent network access to trigger an unauthorized factory reset of the device.

Business impact

With a CVSS score of 9.8, this vulnerability represents a critical risk to physical infrastructure availability. Unauthorized factory resets can lead to significant operational downtime and require manual reconfiguration of the impacted charging stations, causing service disruption.

Remediation

Immediate Action: Update the firmware for the UniFi Connect EV Station Pro to the version recommended in the official Ubiquiti security bulletin.

Proactive Monitoring: Monitor device status logs for unexpected reboot events or configuration changes that may indicate unauthorized access attempts.

Compensating Controls: Restrict physical access to the device and ensure the management interface is isolated from untrusted network segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the UniFi Connect EV Station Pro must apply the provided firmware update immediately to prevent unauthorized device resets. Ensure that all hardware management interfaces are secured behind appropriate network access controls to mitigate the risk of adjacent exploitation.

More Ubiquiti Inc CVEs