CVE-2025-27213
Last modified
CVE-2025-27213 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect Display (Version 1.9.324 and earlier) UniFi Connect Display Cast (Version 1.9.301 and earlier) UniFi Connect Display Cast Pro (Version 1.0.78 and earlier) UniFi Connect Display Cast Lite (Version 1.0.3 and earlier) Mitigation: Update UniFi Connect EV Station Pro to Version 1.5.27 or later Update UniFi Connect Display to Version 1.13.6 or later Update UniFi Connect Display Cast to Version 1.10.3 or later Update UniFi Connect Display Cast Pro to Version 1.0.83 or later Update UniFi Connect Display Cast Lite to Version 1.1.3 or later. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect Display (Version 1.9.324 and earlier) UniFi Connect Display Cast (Version 1.9.301 and earlier) UniFi Connect Display Cast Pro (Version 1.0.78 and earlier) UniFi Connect Display Cast Lite (Version 1.0.3 and earlier) Mitigation: Update UniFi Connect EV Station Pro to Version 1.5.27 or later Update UniFi Connect Display to Version 1.13.6 or later Update UniFi Connect Display Cast to Version 1.10.3 or later Update UniFi Connect Display Cast Pro to Version 1.0.83 or later Update UniFi Connect Display Cast Lite to Version 1.1.3 or later
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-27213?
How severe is CVE-2025-27213?
How do I fix CVE-2025-27213?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27208A reflected Cross-Site Scripting (XSS) vulnerability has bee…6.1
- CVE-2025-27209The V8 release used in Node.js v24.0.0 has changed how strin…7.5
- CVE-2025-2721Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-27210An incomplete fix has been identified for CVE-2025-23084 in …7.5
- CVE-2025-27211An Improper Input Validation in EdgeMAX EdgeSwitch (Version …7.5
- CVE-2025-27212An Improper Input Validation in certain UniFi Access devices…9.8
- CVE-2025-27214A Missing Authentication for Critical Function vulnerability…9.8
- CVE-2025-27215An Improper Access Control could allow a malicious actor aut…8.1
- CVE-2025-27216Multiple Incorrect Permission Assignment for Critical Resour…8.8
- CVE-2025-27217A Server-Side Request Forgery (SSRF) in the UISP Application…9.1
- CVE-2025-27218Sitecore Experience Manager (XM) and Experience Platform (XP…5.3
- CVE-2025-27219In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse …7.5
Are you affected by CVE-2025-27213?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
