ZDI-25-376: (Pwn2Own) Ubiquiti Networks AI Bullet Improper Certificate Validation Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected Ubiquiti Networks AI Bullet cameras. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-23118.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-376?
The severity of ZDI-25-376 is rated at 7.5 on the CVSS scale.
What does the ZDI-25-376 vulnerability allow attackers to do?
ZDI-25-376 allows network-adjacent attackers to bypass authentication on affected Ubiquiti Networks AI Bullet cameras.
Is authentication required to exploit ZDI-25-376?
No, authentication is not required to exploit ZDI-25-376.
What is the impact of ZDI-25-376?
The impact of ZDI-25-376 includes unauthorized access to the affected Ubiquiti Networks AI Bullet cameras.
How can organizations mitigate ZDI-25-376?
Organizations should apply available patches and updates provided by Ubiquiti Networks for the AI Bullet cameras to mitigate ZDI-25-376.