CVE-2020-27888: UI UniFi Controller Firmware

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.

Affected products

  • UI UniFi Controller Firmware: version 6.0.28 only
  • UI UniFi Meshing Access Point Firmware: version 4.3.21.11325 only

Published 2020-10-27. Last modified 2026-06-17.