CVE-2024-45205: Ubiquiti UniFi IOS App
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation: UniFi iOS App (Version 10.18.0 or later).
Affected products
- Ubiquiti UniFi IOS App: before 10.18.0 (fixed in 10.18.0); from 10.18.0
- UI UniFi: before 10.18.0 (fixed in 10.18.0)
Published 2024-12-04. Last modified 2026-06-17.