Description

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

INFO

Published Date :

2025-10-30T23:30:28.329Z

Last Modified :

2025-10-31T14:07:27.850Z

Source :

hackerone
AFFECTED PRODUCTS

The following products are affected by CVE-2025-52665 vulnerability.

Vendors Products
Ui
  • Unifi Access Points
  • Unifi Os
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-52665.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact