CVE-2025-27213 – Ubiquiti UniFi Connect Improper Access Control Vulnerability

The following table lists the changes that have been made to the
CVE-2025-27213 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 21, 2025

    Action Type Old Value New Value
    Added Description An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system.

    Affected Products:

    UniFi Connect EV Station Pro (Version 1.5.18 and earlier)
    UniFi Connect Display (Version 1.9.324 and earlier)
    UniFi Connect Display Cast (Version 1.9.301 and earlier)
    UniFi Connect Display Cast Pro (Version 1.0.78 and earlier)
    UniFi Connect Display Cast Lite (Version 1.0.3 and earlier)

    Mitigation:

    Update UniFi Connect EV Station Pro to Version 1.5.27 or later
    Update UniFi Connect Display to Version 1.13.6 or later
    Update UniFi Connect Display Cast to Version 1.10.3 or later
    Update UniFi Connect Display Cast Pro to Version 1.0.83 or later
    Update UniFi Connect Display Cast Lite to Version 1.1.3 or later

    Added Reference https://community.ui.com/releases/Security-Advisory-Bulletin-052-052/ac1251ee-5bb5-4cdf-8a71-68acd1775bb6
Share the Post:

Related Posts