CVE-2025-27213

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2025
Last modified:
22/08/2025

Description

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system.<br /> <br /> <br /> <br /> Affected Products:<br /> <br /> UniFi Connect EV Station Pro (Version 1.5.18 and earlier)<br /> UniFi Connect Display (Version 1.9.324 and earlier)<br /> UniFi Connect Display Cast (Version 1.9.301 and earlier)<br /> UniFi Connect Display Cast Pro (Version 1.0.78 and earlier)<br /> UniFi Connect Display Cast Lite (Version 1.0.3 and earlier)<br /> <br /> Mitigation:<br /> <br /> Update UniFi Connect EV Station Pro to Version 1.5.27 or later<br /> Update UniFi Connect Display to Version 1.13.6 or later<br /> Update UniFi Connect Display Cast to Version 1.10.3 or later<br /> Update UniFi Connect Display Cast Pro to Version 1.0.83 or later<br /> Update UniFi Connect Display Cast Lite to Version 1.1.3 or later