ZeroHour

CVE-2025-52665

large

Unauthenticated Management API Exposure in Ubiquiti UniFi Access

CVSS 3.1
10.0 critical
EPSS
41%p99
Published
()
Modified
AI analysis

CVE-2025-52665 is a missing-authentication flaw (CWE-306) in Ubiquiti's UniFi Access door-access application, in which a misconfiguration left a management API reachable without proper authentication. To trigger it, an attacker only needs to reach the management network and send requests directly to the unauthenticated API, with no credentials or user interaction required. Because the API controls management functions of the access system, an attacker could read or alter access configuration and sensitive data and potentially disrupt operations (scored 10.0 with high confidentiality, integrity and availability impact and a changed scope, implying possible impact beyond the application itself, such as the hosting UniFi OS console or controlled doors). Only deployments running UniFi Access Application versions 3.3.22 through 3.4.31 are affected, and the issue is fixed in version 4.0.21 and later. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no confirmed in-the-wild exploitation is known, though the high EPSS score (41% probability of exploitation within 30 days, 99th percentile) indicates elevated near-term risk.

What to do: Upgrade the UniFi Access Application to version 4.0.21 or later on any UniFi OS console running versions 3.3.22–3.4.31. As an interim mitigation, restrict and isolate the management network so untrusted clients cannot reach the Access management API. After patching, review logs for unexpected or unauthenticated API calls from the management network to check for prior access.

Affected
Ubiquiti (ui) UniFi Access Application3.3.22 through 3.4.31 (introduced in 3.3.22; fixed in 4.0.21 and later)
Estimated exposure
largeroughly 10,000–100,000 deployments running affected versions — Ubiquiti has a very large installed base of UniFi OS consoles (millions of devices shipped), and UniFi Access is a growing but minority business-oriented application within it, narrowed further to sites still running the 3.3.22–3.4.31…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

Vendors
ui
Products
unifi access
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news