Impact
A path traversal flaw in UniFi Protect Floodlight devices allows a network‑connected attacker to read arbitrary files stored on the device. Exploitation requires only that the attacker can reach the device’s web or management interface; by sending requests containing crafted directory traversal sequences, the attacker can bypass the intended file path boundaries and disclose sensitive configuration or system files. The vulnerability is a classic input validation error (CWE‑22) and does not provide code execution, privilege escalation, or denial of service.
Affected Systems
The vulnerability affects devices built by Ubiquiti Inc under the UniFi Protect Floodlight line. The advisory does not enumerate specific firmware or hardware revisions, so any device that incorporates the vulnerable component could be impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity flaw that primarily threatens confidentiality. The EPSS score of < 1 % highlights a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, a local‑network attacker who can reach the floodlight’s management or API endpoints can craft a request that traverses directories and reads files outside the intended root. Therefore, mitigation through firmware updates and network segmentation is critical to reduce risk, even though the probability of exploitation is currently low.
OpenCVE Enrichment