Impact
This vulnerability allows an attacker who can reach the UniFi Protect AI Key from the network to gain elevated privileges on the device, potentially enabling full control of configuration, data, and network traffic. The flaw is an Improper Access Control issue (CWE‑284) that can compromise the confidentiality, integrity, and availability of the device and any connected services.
Affected Systems
Ubiquiti Inc’s UniFi Protect AI Key product is affected. No specific version range is disclosed, so all currently deployed units should be considered at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and while an EPSS score is not available, the attack would be straightforward for anyone with network access to the device. The issue is not listed in the CISA KEV catalog, but the high CVSS suggests a significant threat profile. The likely attack vector is network-based access to the device, exploiting the access control weakness to elevate privileges.
OpenCVE Enrichment