CVE-2026-21635: UI UniFi Connect Ev Station Lite Firmware

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet.

Affected products

  • UI UniFi Connect Ev Station Lite Firmware: before 1.6.1 (fixed in 1.6.1)

Published 2026-01-05. Last modified 2026-06-17.