CVE-2025-23091: Ubiquiti Inc Efg
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.
Affected products
- Ubiquiti Inc Efg: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Ucg-Max: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Uck: before 4.1.11 (fixed in 4.1.11)
- Ubiquiti Inc Uck-Enterprise: before 4.1.11 (fixed in 4.1.11)
- Ubiquiti Inc Uckp: before 4.1.11 (fixed in 4.1.11)
- Ubiquiti Inc Udm: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Udm-Pro: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Udm-Pro-Max: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Udm-SE: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Udw: before 4.1.13 (fixed in 4.1.13)
- Ubiquiti Inc Unvr: before 4.1.11 (fixed in 4.1.11)
- Ubiquiti Inc Unvr Pro: before 4.1.11 (fixed in 4.1.11)
Published 2025-02-01. Last modified 2026-06-17.