Impact
Path Traversal vulnerability that allows an attacker with network access to read any file on the host device. The flaw results from insufficient validation or sanitisation of file path inputs and is classified as a means thereby compromising the confidentiality of the device and potentially the organization relying on it.
Affected Systems
The vulnerability affects Ubiquiti Inc’s UniFi Access Application. No specific version numbers are disclosed, so all installations that have not applied the vendor’s fix remain vulnerable. The flaw impacts devices connected to the same network as the application.
Risk and Exploitability
Based on the description, the likely attack vector is network-based; the attacker must reach the device over the network or an exposed interface. The CVSS score of 8.6. EPSS score is <1%, suggesting a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw allows arbitrary file reads, a successful exploit could reveal configuration data, credentials, or logs and thereby compromise confidentiality.
OpenCVE Enrichment