CVE-2025-27212
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
04/08/2025
Last modified:
05/08/2025
Description
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network.<br />
<br />
<br />
<br />
Affected Products:<br />
UniFi Access Reader Pro (Version 2.14.21 and earlier)<br />
UniFi Access G2 Reader Pro (Version 1.10.32 and earlier)<br />
UniFi Access G3 Reader Pro (Version 1.10.30 and earlier)<br />
UniFi Access Intercom (Version 1.7.28 and earlier)<br />
UniFi Access G3 Intercom (Version 1.7.29 and earlier)<br />
UniFi Access Intercom Viewer (Version 1.3.20 and earlier)<br />
<br />
<br />
<br />
Mitigation:<br />
Update UniFi Access Reader Pro Version 2.15.9 or later<br />
Update UniFi Access G2 Reader Pro Version 1.11.23 or later<br />
Update UniFi Access G3 Reader Pro Version 1.11.22 or later<br />
Update UniFi Access Intercom Version 1.8.22 or later<br />
Update UniFi Access G3 Intercom Version 1.8.22 or later<br />
Update UniFi Access Intercom Viewer Version 1.4.39 or later
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



