CVE-2025-24285
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
21/08/2025
Last modified:
22/08/2025
Description
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite.<br />
<br />
Affected Products:<br />
UniFi Connect EV Station Lite (Version 1.5.1 and earlier)<br />
<br />
Mitigation:<br />
Update UniFi Connect EV Station Lite to Version 1.5.2 or later
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



