CVE-2025-52665Disclosure(ui / unifi_access)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unifi_access

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
unifi_access

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-18: 103-18
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Ananay@ananayarora
    Disclosure

    This is the THIRD CVS 10.0 vulnerability for UniFi in the past year CVE-2025-23123, CVE-2025-52665, CVE-2026-22557.

    Post summary

    The post lists three CVE identifiers for UniFi vulnerabilities, but provides no technical details, exploitation information, or mitigation guidance.

    10060904
    13.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuiunifi_access---

Explore more