CVE-2020-8148: UI Cloud Key GEN2

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicious API request. This affects Cloud Key gen2 and Cloud Key gen2 Plus.

Affected products

  • UI Cloud Key GEN2: up to and including 1.1.6
  • UI Cloud Key GEN2 Plus: up to and including 1.1.6

Published 2020-04-13. Last modified 2026-06-17.