ZDI-25-377: (Pwn2Own) Ubiquiti Networks AI Bullet Improper Neutralization of Escape Sequences Authentication Bypass Vulnerability
Published Jun 11, 2025
·Updated
This vulnerability allows network-adjacent attackers to bypass authentication on affected Ubiquiti Networks AI Bullet cameras. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-23119.
Affected Software
1 affected component
Ubiquiti Networks AI Bullet
Event History
Jun 11, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-377?
The severity of ZDI-25-377 is rated at 7.5 on the CVSS scale.
2
How do I fix ZDI-25-377?
To address ZDI-25-377, ensure that all affected Ubiquiti Networks AI Bullet cameras are updated to the latest firmware version released by Ubiquiti.
3
What type of attacks does ZDI-25-377 allow?
ZDI-25-377 allows network-adjacent attackers to bypass authentication on the affected cameras.
4
Do I need authentication to exploit ZDI-25-377?
No, authentication is not required to exploit ZDI-25-377.
5
Which devices are affected by ZDI-25-377?
ZDI-25-377 affects Ubiquiti Networks AI Bullet cameras.