CVE detail
CVE-2025-52665 — CVE-2025-52665
Published 2025-10-31 · Modified 2026-06-17 · Vendor ui · Product unifi_access · Source nvd
CRITICAL
severity
CVSS-derived band
0.4097
EPSS probability
exploitation probability, 30d
99.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.
Affected Products:
UniFi Access Application (Version 3.3.22 through 3.4.31).
Mitigation:
Update your UniFi Access Application to Version 4.0.21 or later.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References