CVE-2025-52665
largeUnauthenticated Management API Exposure in Ubiquiti UniFi Access
CVE-2025-52665 is a missing-authentication flaw (CWE-306) in Ubiquiti's UniFi Access door-access application, in which a misconfiguration left a management API reachable without proper authentication. To trigger it, an attacker only needs to reach the management network and send requests directly to the unauthenticated API, with no credentials or user interaction required. Because the API controls management functions of the access system, an attacker could read or alter access configuration and sensitive data and potentially disrupt operations (scored 10.0 with high confidentiality, integrity and availability impact and a changed scope, implying possible impact beyond the application itself, such as the hosting UniFi OS console or controlled doors). Only deployments running UniFi Access Application versions 3.3.22 through 3.4.31 are affected, and the issue is fixed in version 4.0.21 and later. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no confirmed in-the-wild exploitation is known, though the high EPSS score (41% probability of exploitation within 30 days, 99th percentile) indicates elevated near-term risk.
What to do: Upgrade the UniFi Access Application to version 4.0.21 or later on any UniFi OS console running versions 3.3.22–3.4.31. As an interim mitigation, restrict and isolate the management network so untrusted clients cannot reach the Access management API. After patching, review logs for unexpected or unauthenticated API calls from the management network to check for prior access.
| Ubiquiti (ui) UniFi Access Application | 3.3.22 through 3.4.31 (introduced in 3.3.22; fixed in 4.0.21 and later) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.
- Vendors
- ui
- Products
- unifi access
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H