CVE-2014-2226: UI UniFi Controller

Low severity, CVSS 2.6. EPSS: 1.5% chance of exploitation in the next 30 days.

Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

Affected products

  • UI UniFi Controller: up to and including 2.4.6

Published 2014-07-29. Last modified 2026-06-17.