ZDI-CAN-28474: ZDI-26-127: (Pwn2Own) Ubiquiti Networks AI Pro Cleartext Transmission Information Disclosure Vulnerability
Published Feb 25, 2026
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Ubiquiti Networks AI Pro. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-21633.
Affected Software
1 affected component
Ubiquiti Networks AI Pro
Event History
Feb 25, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28474?
The CVSS rating for ZDI-CAN-28474 is 5.3, indicating a medium severity level.
2
How do I fix ZDI-CAN-28474?
To mitigate ZDI-CAN-28474, ensure that all sensitive information is transmitted over secure protocols.
3
Who is affected by ZDI-CAN-28474?
ZDI-CAN-28474 affects installations of Ubiquiti Networks AI Pro that are network-adjacent.
4
Is authentication required to exploit ZDI-CAN-28474?
No, ZDI-CAN-28474 can be exploited by attackers without requiring authentication.
5
What kind of information does ZDI-CAN-28474 disclose?
ZDI-CAN-28474 allows attackers to disclose sensitive information transmitted in cleartext.