CVE-2025-23164: Medium severity ubiquiti unifi protect application vulnerability
A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share Livestream" link to maintain access to the corresponding livestream subsequent to such link becoming disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23164?
CVE-2025-23164 is considered a high severity vulnerability due to the potential unauthorized access to livestreams.
How do I fix CVE-2025-23164?
To fix CVE-2025-23164, upgrade the Unifi Protect Application to version 5.3.42 or later where the access token mechanism is properly configured.
What are the risks associated with CVE-2025-23164?
The risks include unauthorized viewers maintaining access to livestreams after shared links are disabled.
Which versions are affected by CVE-2025-23164?
CVE-2025-23164 affects Ubiquiti Unifi Protect Application versions up to and including 5.3.41.
Is there a workaround for CVE-2025-23164?
No official workarounds are provided for CVE-2025-23164; upgrading to a patched version is the recommended solution.