CVE-2020-27888: High severity ubiquiti unifi meshing access point vulnerability
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27888?
The severity of CVE-2020-27888 is high with a severity value of 7.5.
Which devices are affected by CVE-2020-27888?
Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices are affected by CVE-2020-27888.
What is the issue with CVE-2020-27888?
Cached credentials are not erased from an access point returning wirelessly from a disconnected state, which may provide unintended network access.
How can I fix CVE-2020-27888?
There is currently no fix available for CVE-2020-27888. It is recommended to follow the vendor's security advisory for updates.
Where can I find more information about CVE-2020-27888?
More information about CVE-2020-27888 can be found at the following reference: [link](https://community.ui.com/questions/Possible-authentication-bypass-for-access-into-LAN/7965adb2-5d70-4410-8467-4c7bec76bc00)