ZDI-CAN-28274: ZDI-26-126: (Pwn2Own) Ubiquiti Networks AI Pro Discovery Protocol Missing Encryption Protocol Downgrade Vulnerability
This vulnerability allows network-adjacent attackers to downgrade the communication protocol on affected installations of Ubiquiti Networks AI Pro. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-21633.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28274?
The CVSS rating for ZDI-CAN-28274 is 5.4, indicating a moderate severity level.
How do I fix ZDI-CAN-28274?
To mitigate ZDI-CAN-28274, ensure that your Ubiquiti Networks AI Pro installations are updated to the latest firmware version that addresses the vulnerability.
Who can exploit the ZDI-CAN-28274 vulnerability?
The vulnerability can be exploited by network-adjacent attackers without requiring authentication.
What type of vulnerability is ZDI-CAN-28274?
ZDI-CAN-28274 is classified as a missing encryption protocol downgrade vulnerability.
What is affected by ZDI-CAN-28274?
ZDI-CAN-28274 affects installations of Ubiquiti Networks AI Pro.