CVE-2025-52665 describes a critical authentication bypass vulnerability in UniFi Access Application versions 3.3.22 through 3.4.31. A malicious actor on the management network could exploit a misconfigured management API to gain unauthorized access. This vulnerability carries a CVSS score of 10.0 (CRITICAL) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not currently in the KEV catalog, exploit intelligence indicates the existence of Nuclei templates for "Broken Access Control" and there is significant community discussion, with some posts referencing unauthenticated RCE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.3.22, < 4.0.21CPE matchmatch criteria | cpe:2.3:a:ui:unifi_access:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.