ZDI-26-127: (Pwn2Own) Ubiquiti Networks AI Pro Cleartext Transmission Information Disclosure Vulnerability
Published Feb 25, 2026
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Ubiquiti Networks AI Pro. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-21633.
Affected Software
1 affected component
Ubiquiti Networks AI Pro
Event History
Feb 25, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-127?
The severity of ZDI-26-127 is rated at 5.3 according to the CVSS scoring system.
2
How do I fix ZDI-26-127?
To fix ZDI-26-127, ensure that you apply the latest security patches provided by Ubiquiti Networks for the AI Pro software.
3
What type of attack does ZDI-26-127 allow?
ZDI-26-127 allows network-adjacent attackers to disclose sensitive information without requiring authentication.
4
What products are affected by ZDI-26-127?
ZDI-26-127 affects installations of Ubiquiti Networks AI Pro.
5
Is authentication required to exploit ZDI-26-127?
No, authentication is not required to exploit the ZDI-26-127 vulnerability.