CVE-2025-52665

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
31/10/2025
Last modified:
12/11/2025

Description

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. <br /> <br /> Affected Products:<br /> UniFi Access Application (Version 3.3.22 through 3.4.31). 
 <br /> <br /> Mitigation:<br /> Update your UniFi Access Application to Version 4.0.21 or later.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ui:unifi_access:*:*:*:*:*:*:*:* 3.3.22 (including) 4.0.21 (excluding)