ZDI-25-379: (Pwn2Own) Ubiquiti Networks AI Bullet Insufficient Firmware Update Validation Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Ubiquiti Networks AI Bullet Cameras. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2025-23117.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-379?
ZDI-25-379 has a high severity rating due to its ability to allow arbitrary code execution.
How do I fix ZDI-25-379?
To mitigate ZDI-25-379, ensure that your Ubiquiti Networks AI Bullet Cameras are updated to the latest firmware version provided by the vendor.
Who is affected by ZDI-25-379?
The vulnerability ZDI-25-379 affects users of Ubiquiti Networks AI Bullet Cameras.
Can ZDI-25-379 be exploited remotely?
Exploitation of ZDI-25-379 requires network adjacency, meaning an attacker must be on the same local network.
Is authentication required for ZDI-25-379 exploitation?
Yes, although authentication is required, the vulnerability allows the authentication mechanism to be bypassed.