Логотип exploitDog
bind:CVE-2025-52665
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-52665

Количество 3

Количество 3

nvd логотип

CVE-2025-52665

3 месяца назад

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-2rj5-gh6q-72fp

3 месяца назад

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
EPSS: Средний
fstec логотип

BDU:2026-00253

4 месяца назад

Уязвимость системы контроля доступа UniFi Access, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный контроль над системой

CVSS3: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-52665

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
11%
Средний
3 месяца назад
github логотип
GHSA-2rj5-gh6q-72fp

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
11%
Средний
3 месяца назад
fstec логотип
BDU:2026-00253

Уязвимость системы контроля доступа UniFi Access, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный контроль над системой

CVSS3: 10
11%
Средний
4 месяца назад

Уязвимостей на страницу