CVE-2020-27888: UI UniFi Controller Firmware
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.
Affected products
- UI UniFi Controller Firmware: version 6.0.28 only
- UI UniFi Meshing Access Point Firmware: version 4.3.21.11325 only
Published 2020-10-27. Last modified 2026-06-17.