Improper Input Validation in UniFi Access Devices by Ubiquiti Networks
CVE-2025-27212

9.8CRITICAL

What is CVE-2025-27212?

A flaw in the input validation process of specific UniFi Access devices could permit a malicious actor to execute command injection attacks. This vulnerability emphasizes the importance of securing management networks and updating affected products to prevent unauthorized access.

Affected Version(s)

UniFi Access G2 Reader Pro 1.11.23

UniFi Access G3 Intercom 1.8.22

UniFi Access G3 Reader Pro 1.11.22

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27212 : Improper Input Validation in UniFi Access Devices by Ubiquiti Networks