Improper Access Control in UniFi Connect Products by Ubiquiti Networks
CVE-2025-27213

4.9MEDIUM

What is CVE-2025-27213?

An Improper Access Control vulnerability exists in certain UniFi Connect devices, allowing authenticated malicious actors to enable Android Debug Bridge (ADB). This could lead to unauthorized changes to the system, posing significant security risks. Users are advised to update to the latest versions of affected products to mitigate these vulnerabilities.

Affected Version(s)

UniFi Connect Display 1.13.6

UniFi Connect Display Cast 1.10.3

UniFi Connect Display Cast Lite 1.1.3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.