CVE-2025-27213

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect Display (Version 1.9.324 and earlier) UniFi Connect Display Cast (Version 1.9.301 and earlier) UniFi Connect Display Cast Pro (Version 1.0.78 and earlier) UniFi Connect Display Cast Lite (Version 1.0.3 and earlier) Mitigation: Update UniFi Connect EV Station Pro to Version 1.5.27 or later Update UniFi Connect Display to Version 1.13.6 or later Update UniFi Connect Display Cast to Version 1.10.3 or later Update UniFi Connect Display Cast Pro to Version 1.0.83 or later Update UniFi Connect Display Cast Lite to Version 1.1.3 or later
Configurations

No configuration.

History

21 Aug 2025, 14:15

Type Values Removed Values Added
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
Summary
  • (es) Un control de acceso inadecuado podría permitir que un agente malicioso autenticado en la API de ciertos dispositivos UniFi Connect habilite Android Debug Bridge (ADB) y realice cambios no admitidos en el sistema. Productos afectados: UniFi Connect EV Station Pro (versión 1.5.18 y anteriores), UniFi Connect Display (versión 1.9.324 y anteriores), UniFi Connect Display Cast (versión 1.9.301 y anteriores), UniFi Connect Display Cast Pro (versión 1.0.78 y anteriores), UniFi Connect Display Cast Lite (versión 1.0.3 y anteriores). Mitigación: Actualizar UniFi Connect EV Station Pro a la versión 1.5.27 o posterior. Actualizar UniFi Connect Display a la versión 1.13.6 o posterior. Actualizar UniFi Connect Display Cast a la versión 1.10.3 o posterior. Actualizar UniFi Connect Display Cast Pro a la versión 1.0.83 o posterior. Actualizar UniFi Connect Display Cast Lite a la versión 1.1.3 o posterior.

21 Aug 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 01:15

Updated : 2025-08-22 18:09


NVD link : CVE-2025-27213

Mitre link : CVE-2025-27213

CVE.ORG link : CVE-2025-27213


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization