CVE-2025-27215
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
21/08/2025
Last modified:
22/08/2025
Description
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system.<br />
<br />
<br />
<br />
Affected Products:<br />
<br />
UniFi Connect Display Cast (Version 1.10.3 and earlier)<br />
UniFi Connect Display Cast Pro (Version 1.0.89 and earlier)<br />
UniFi Connect Display Cast Lite (Version 1.0.3 and earlier)<br />
<br />
<br />
<br />
Mitigation:<br />
<br />
Update UniFi Connect Display Cast to Version 1.10.7 or later<br />
Update UniFi Connect Display Cast Pro to Version 1.0.94 or later<br />
Update UniFi Connect Display Cast Lite to Version 1.1.8 or later
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH



