CVE-2025-27214: Critical severity Ubiquiti UniFi Connect EV Station Pro vulnerability
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) Mitigation: Update UniFi Connect EV Station Pro to Version 1.5.27 or later
Affected Software
Event History
Frequently Asked Questions
What is the CVE-2025-27214 vulnerability?
CVE-2025-27214 is a Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro that allows unauthorized factory resets by adjacent attackers.
What is the severity of CVE-2025-27214?
The severity of CVE-2025-27214 is considered high due to the potential for unauthorized access and system reset.
How do I fix CVE-2025-27214?
To fix CVE-2025-27214, upgrade the UniFi Connect EV Station Pro to version 1.5.19 or later.
Who is affected by CVE-2025-27214?
Users of UniFi Connect EV Station Pro versions 1.5.18 and earlier are affected by CVE-2025-27214.
What actions can a malicious actor take with CVE-2025-27214?
A malicious actor with physical or adjacent access can perform an unauthorized factory reset on the affected device.