CVE-2025-27217
9.1Ubiquiti Inc · UISP Application
A Server-Side Request Forgery (SSRF) vulnerability in the Ubiquiti UISP Application allows unauthorized actors to perform requests outside the intended application scope.
Executive summary
A critical Server-Side Request Forgery vulnerability in the Ubiquiti UISP Application exposes the system to unauthorized request execution, necessitating immediate patching.
Vulnerability
This is an SSRF vulnerability where the application fails to properly validate requests, allowing an unauthenticated attacker to interact with internal resources or external services.
Business impact
The flaw carries a CVSS score of 9.1, indicating a critical severity level. Successful exploitation could lead to unauthorized access to internal network services, information disclosure, or the potential for further lateral movement within the infrastructure, posing a significant risk to organizational security.
Remediation
Immediate Action: Update the Ubiquiti UISP Application to the latest version as specified in the vendor security advisory.
Proactive Monitoring: Review application and network access logs for unusual outbound requests or connections originating from the UISP server to internal network segments.
Compensating Controls: Implement strict egress filtering on the host running the UISP application to prevent unauthorized communication with sensitive internal resources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS score and the potential for network-level compromise, administrators should prioritize updating the UISP Application immediately. Failure to patch leaves the internal network exposed to unauthorized reconnaissance and potential data exfiltration.