CVE-2024-45205: Ubiquiti UniFi IOS App

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation: UniFi iOS App (Version 10.18.0 or later).

Affected products

  • Ubiquiti UniFi IOS App: before 10.18.0 (fixed in 10.18.0); from 10.18.0
  • UI UniFi: before 10.18.0 (fixed in 10.18.0)

Published 2024-12-04. Last modified 2026-06-17.