CVE-2025-24290: Ubiquiti Inc Uisp Application

Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.

Affected products

  • Ubiquiti Inc Uisp Application: before 2.4.211 (fixed in 2.4.211)

Published 2025-06-29. Last modified 2026-06-17.