Authenticated SQL Injection Vulnerability in UISP Application by Ubiquiti
CVE-2025-24290

9.9CRITICAL

Key Information:

Vendor
CVE Published:
29 June 2025

What is CVE-2025-24290?

Multiple authenticated SQL injection vulnerabilities exist in the UISP Application versions 2.4.206 and earlier. These vulnerabilities may allow an attacker with low-level access to escalate their privileges, potentially granting unauthorized access to sensitive functions and data. Immediate action is advised to mitigate risks associated with these vulnerabilities.

Affected Version(s)

UISP Application 2.4.211

References

CVSS V3.0

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24290 : Authenticated SQL Injection Vulnerability in UISP Application by Ubiquiti