CVE-2025-52665: Critical severity UniFi Access Application vulnerability
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31).
Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52665?
CVE-2025-52665 has a high severity rating due to the lack of authentication on a management API in UniFi Access.
How do I fix CVE-2025-52665?
To fix CVE-2025-52665, upgrade your UniFi Access application to version 4.0.21 or later.
What versions of UniFi Access are affected by CVE-2025-52665?
CVE-2025-52665 affects UniFi Access versions from 3.3.22 to 3.4.31.
Who can exploit CVE-2025-52665?
A malicious actor with access to the management network can exploit CVE-2025-52665.
When was CVE-2025-52665 introduced?
CVE-2025-52665 was introduced in version 3.3.22 of the UniFi Access application.