CVE-2024-34786: Ubiquiti UniFi IOS App

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later.

Affected products

  • Ubiquiti UniFi IOS App: before 10.15.2 (fixed in 10.15.2)

Published 2024-07-09. Last modified 2026-06-17.