CVE-2025-23116: Ubiquiti Inc UniFi Protect Application
Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.
An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to take control of UniFi Protect Cameras.
Affected products
- Ubiquiti Inc UniFi Protect Application: before 5.2.49 (fixed in 5.2.49)
Published 2025-03-01. Last modified 2026-06-17.