Impact
The vulnerability is an Improper Initialization flaw (CWE‑665) in the UniFi Protect Application that can allow an attacker who can reach the local network to send unauthenticated requests that leave the application in a state where it accepts those requests as legitimate. Once this state is achieved, an attacker gains unauthorized access to camera feeds or control functions, effectively bypassing authentication and compromising confidentiality, integrity, and availability of the surveillance system.
Affected Systems
The issue impacts Ubiquiti Inc’s UniFi Protect Application and any UniFi Protect Cameras that rely on that application for authentication. Because specific affected software versions are not listed, all current releases of the application and associated camera firmware should be treated as potentially vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or segment‑level network access, as the attacker must be able to send special unauthenticated requests to the Protect Application to trigger improper initialization. No publicly observed widespread exploitation is known, but the potential impact of local‑network credential bypass remains significant.
OpenCVE Enrichment