CVE-2025-27212

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/08/2025
Last modified:
05/08/2025

Description

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network.<br /> <br /> <br /> <br /> Affected Products:<br /> UniFi Access Reader Pro (Version 2.14.21 and earlier)<br /> UniFi Access G2 Reader Pro (Version 1.10.32 and earlier)<br /> UniFi Access G3 Reader Pro (Version 1.10.30 and earlier)<br /> UniFi Access Intercom (Version 1.7.28 and earlier)<br /> UniFi Access G3 Intercom (Version 1.7.29 and earlier)<br /> UniFi Access Intercom Viewer (Version 1.3.20 and earlier)<br /> <br /> <br /> <br /> Mitigation:<br /> Update UniFi Access Reader Pro Version 2.15.9 or later<br /> Update UniFi Access G2 Reader Pro Version 1.11.23 or later<br /> Update UniFi Access G3 Reader Pro Version 1.11.22 or later<br /> Update UniFi Access Intercom Version 1.8.22 or later<br /> Update UniFi Access G3 Intercom Version 1.8.22 or later<br /> Update UniFi Access Intercom Viewer Version 1.4.39 or later