ZDI-CAN-25603: ZDI-25-377: (Pwn2Own) Ubiquiti Networks AI Bullet Improper Neutralization of Escape Sequences Authentication Bypass Vulnerability
Published Jun 11, 2025
·Updated
This vulnerability allows network-adjacent attackers to bypass authentication on affected Ubiquiti Networks AI Bullet cameras. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-23119.
Affected Software
1 affected component
Ubiquiti Networks AI Bullet
Event History
Jun 11, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25603?
The severity of ZDI-CAN-25603 is rated at 7.5 on the CVSS scale.
2
How do I fix ZDI-CAN-25603?
To fix ZDI-CAN-25603, update your Ubiquiti Networks AI Bullet camera to the latest firmware version provided by the manufacturer.
3
Who is affected by ZDI-CAN-25603?
ZDI-CAN-25603 affects users of Ubiquiti Networks AI Bullet cameras.
4
What type of attacker can exploit ZDI-CAN-25603?
Network-adjacent attackers can exploit ZDI-CAN-25603 to bypass authentication.
5
Is authentication required to exploit ZDI-CAN-25603?
No, authentication is not required to exploit ZDI-CAN-25603.