Authentication Bypass in UniFi Network by Ubiquiti
CVE-2025-24292

6.8MEDIUM

Key Information:

Vendor
CVE Published:
29 June 2025

What is CVE-2025-24292?

A misconfigured query in the UniFi Network product could lead to an authentication bypass, enabling users to access the Enterprise WiFi or VPN server by exploiting their device’s MAC address utilized in 802.1X or MAC Authentication scenarios. This vulnerability occurs when both services operate using the same RADIUS profile, highlighting the importance of proper configuration and security measures in network authentication protocols.

Affected Version(s)

UniFi Network Application 9.2.87

References

CVSS V3.0

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24292 : Authentication Bypass in UniFi Network by Ubiquiti