Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8148

20
FAUCET Score

CVE-2020-8148 describes a vulnerability in UniFi Cloud Key firmware versions prior to 1.1.6, affecting Cloud Key Gen2 and Gen2 Plus devices. An unauthenticated attacker can exploit this flaw by sending a malicious API request to arbitrarily change the device's hostname. Rated Medium severity (CVSS 5.3), this network-based attack requires low complexity and has a low impact on integrity, as it only allows for hostname modification. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.1.6CPE matchmatch criteria
cpe:2.3:o:ui:cloud_key_gen2:*:*:*:*:*:*:*:*
<= 1.1.6CPE matchmatch criteria
cpe:2.3:o:ui:cloud_key_gen2_plus:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.03%
Probability of exploitation in next 30 days
EPSS Percentile
60.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0103 is in the 38th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

boschvendor investigatingvia llm_extracted
maxkbvendor investigatingvia llm_extracted
nxpvendor investigatingvia llm_extracted
openfirevendor investigatingvia llm_extracted
openstackvendor investigatingvia llm_extracted
opnsensevendor investigatingvia llm_extracted

Vendor Advisories (6)

maxkbllm-maxkb-c01cc99b7f243c6eMEDIUM

Ubiquiti Unifi Cloud Key Gen2 Plus Unauthenticated Hostname Modification

Apr 9, 2020
openstackllm-openstack-23718855a997d70dMEDIUM

Ubiquiti Unifi Cloud Key Gen2 Plus Unauthenticated Hostname Modification

Apr 9, 2020
nxpllm-nxp-8b8ead2970c079d2MEDIUM

Ubiquiti Unifi Cloud Key Gen2 Plus Unauthenticated Hostname Modification

Apr 9, 2020
boschllm-bosch-d547cf870b7beafeMEDIUM

Ubiquiti Unifi Cloud Key Gen2 Plus Unauthenticated Hostname Modification

Apr 9, 2020
opnsensellm-opnsense-35c22306d54f8ac3MEDIUM

Ubiquiti Unifi Cloud Key Gen2 Plus Unauthenticated Hostname Modification

Apr 9, 2020
openfirellm-openfire-2c000c1e5fc9b346MEDIUM

Ubiquiti Unifi Cloud Key Gen2 Plus Unauthenticated Hostname Modification

Apr 9, 2020

References

community.ui.com / releases/Security-advisory-bulletin-007-007/eb639fa0-68ad-4bf5-9663-3b760eb2f93a
PatchVendor Advisory
hackerone.com / reports/802079
Issue TrackingThird Party Advisory