CVE-2019-5456: UI UniFi Controller

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.

Affected products

  • UI UniFi Controller: up to and including 5.10.21

Published 2019-07-30. Last modified 2026-06-17.