Sunday, September 13, 2026

Ubiquiti UniFi Vulnerability Lets Hackers Inject Malicious Commands

A critical security vulnerability has been discovered in Ubiquiti’s UniFi Access devices that could allow malicious actors to inject and execute arbitrary commands on affected systems.

The vulnerability, designated as CVE-2025-27212, affects multiple UniFi Access products and carries a maximum CVSS score of 9.8, indicating its severe nature and potential for widespread exploitation.

Vulnerability Details and Attack Vector

The security flaw stems from improper input validation within certain UniFi Access devices, creating a pathway for command injection attacks.

AttributeDetails
CVE IdentifierCVE-2025-27212
Publication DateJuly 16, 2025
CVSS v3.0 Base Score9.8 (Critical)

Security researchers Bongeun Koo and Junhyung Cho, who discovered the vulnerability, demonstrated that attackers with access to the UniFi Access management network could exploit this weakness to execute malicious commands on targeted devices.

The vulnerability’s high severity rating reflects its potential impact across enterprise environments where UniFi Access systems are commonly deployed for physical access control.

The flaw allows attackers to bypass normal security controls and potentially gain unauthorized access to sensitive areas or systems protected by these devices.

Affected Products and Versions

The vulnerability impacts six distinct UniFi Access product lines, each with specific vulnerable version ranges.

The affected devices include access readers, intercoms, and related hardware that organizations rely on for comprehensive access control solutions.

ProductVulnerable VersionsFixed Versions
UniFi Access Reader Pro2.14.21 and earlier2.15.9 or later
UniFi Access G2 Reader Pro1.10.32 and earlier1.11.23 or later
UniFi Access G3 Reader Pro1.10.30 and earlier1.11.22 or later
UniFi Access Intercom1.7.28 and earlier1.8.22 or later
UniFi Access G3 Intercom1.7.29 and earlier1.8.22 or later
UniFi Access Intercom Viewer1.3.20 and earlier1.4.39 or later

Ubiquiti has released security updates for all affected products, and organizations should prioritize immediate deployment of these patches.

The company’s Security Advisory Bulletin 051 provides comprehensive guidance for system administrators managing these devices.

Given the critical nature of this vulnerability and the potential for unauthorized access to physical security systems, organizations using UniFi Access devices should implement emergency patching procedures and conduct thorough security assessments to ensure no unauthorized access has occurred.

Get Free Ultimate SOC Requirements Checklist Before you build, buy, or switch your SOC for 2025 - Download Now

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News