CVE-2025-27212 - CVE House
Back to Database
Status published Unknown CVE-2025-27212

An Improper Input Validation in certain UniFi Access devices could...

Vulnerability Description

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro (Version 1.10.30 and earlier) UniFi Access Intercom (Version 1.7.28 and earlier) UniFi Access G3 Intercom (Version 1.7.29 and earlier) UniFi Access Intercom Viewer (Version 1.3.20 and earlier) Mitigation: Update UniFi Access Reader Pro Version 2.15.9 or later Update UniFi Access G2 Reader Pro Version 1.11.23 or later Update UniFi Access G3 Reader Pro Version 1.11.22 or later Update UniFi Access Intercom Version 1.8.22 or later Update UniFi Access G3 Intercom Version 1.8.22 or later Update UniFi Access Intercom Viewer Version 1.4.39 or later

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27212

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Ubiquiti Inc

View all reports →

Affected Software

UniFi Access Reader Pro, UniFi Access G2 Reader Pro, UniFi Access G3 Reader Pro, UniFi Access Intercom, UniFi Access G3 Intercom, UniFi Access Intercom Viewer
Vulnerable Versions:
2.15.9, 1.11.23, 1.11.22, 1.8.22, 1.4.39

Timeline

Official Publish: August 4th, 2025
Last Modified: August 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.