S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 5, 2025

CVE-2025-52665 Scanner

CVE-2025-52665 Scanner - Remote Code Execution (RCE) vulnerability in UniFi Access

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-52665
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
UniFi Access Applicationby Ubiquiti Inc
3.3.22
Updated Sep 9, 2026View on NVD →
Detail

UniFi Access is a robust access control system used by businesses and organizations to manage entry points and secure buildings. It offers a scalable solution with integration capabilities for various security devices, providing a comprehensive management platform. UniFi Access is designed to be user-friendly, allowing for easy installation and configuration by IT administrators. This system is typically deployed in environments requiring stringent control over access permissions, ensuring that non-authorized personnel cannot gain entry. Organizations of different sizes leverage this software for its reliability and the convenience of centralized management. Such systems are critical in industries where access to physical locations must be strictly monitored and regulated.

The Remote Code Execution (RCE) vulnerability found in UniFi Access arises from a broken access control misconfiguration. This vulnerability allows attackers to exploit network access to the management APIs without proper authentication. By leveraging this flaw, unauthorized users can potentially gain control over the system, executing arbitrary code. This security lapse exposes sensitive management functions to unauthenticated network users, breaching the intended security layers. Generally, flaws in access control can lead to significant trust and operational issues within affected environments. It underscores the critical need for rigorous configuration management in security-critical applications.

This vulnerability is technically rooted in the way UniFi Access's management API is exposed due to a misconfiguration. It allows HTTP requests to endpoints that should be protected by authentication measures. The vulnerability can be demonstrated by triggering an unauthorized export of a backup through specific tools or scripts. Technically, the software fails to enforce requisite authentication checks on certain API endpoints. This lapse permits attackers to perform operations that would normally require administrative permissions. Identifying such vulnerabilities requires in-depth testing for authentication loopholes in the API surface.

Should this vulnerability be exploited, it could result in unauthorized individuals gaining admin-level access to sensitive management functions. This may lead to the manipulation or theft of data, disruption of system operations, and potentially more severe compromises of additional network systems connected to the affected instance. Such exploits undermine trust in the system's integrity and can have legal or financial repercussions for the organizations involved. Additionally, if left unaddressed, it may provide a foothold for further system infiltrations and exploit chains executed by malicious actors.

REFERENCES

Solution Advice
  • Update UniFi Access to version 4.0.21 or later to mitigate this vulnerability.
  • Regularly review and audit security settings to ensure APIs and sensitive endpoints include robust authentication measures.
  • Implement network segmentation to limit exposure of management interfaces to necessary personnel only.
  • Conduct regular penetration tests to identify and address potential weaknesses in access controls.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.