Vulnerabilities
Vulnerable Software
Ui:  >> Unifi Access  >> 3.3.22  Security Vulnerabilities
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
CVSS Score
8.6
EPSS Score
0.004
Published
2026-07-02
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-07-02
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
CVSS Score
9.9
EPSS Score
0.012
Published
2026-07-02
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). 
 Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.
CVSS Score
10.0
EPSS Score
0.41
Published
2025-10-31


Contact Us

Shodan ® - All rights reserved