ZDI-26-126: (Pwn2Own) Ubiquiti Networks AI Pro Discovery Protocol Missing Encryption Protocol Downgrade Vulnerability
This vulnerability allows network-adjacent attackers to downgrade the communication protocol on affected installations of Ubiquiti Networks AI Pro. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-21633.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-126?
The severity of ZDI-26-126 is rated at 5.4 according to CVSS.
How do I fix ZDI-26-126?
To fix ZDI-26-126, update to the latest version of Ubiquiti Networks AI Pro that addresses this vulnerability.
What type of attacks does ZDI-26-126 allow?
ZDI-26-126 allows network-adjacent attackers to downgrade the communication protocol without requiring authentication.
Which product is affected by ZDI-26-126?
ZDI-26-126 affects Ubiquiti Networks AI Pro installations.
What is the impact of the vulnerability ZDI-26-126?
The impact of ZDI-26-126 can lead to potential exploitation through downgraded communication protocols, compromising the integrity of network communications.