CNNVD-202506-3701 Information

CNNVD ID

CNNVD-202506-3701

CVE-2025-24292

  • CNNVD Published: 2025-06-29

Description (Chinese)

Ubiquiti Networks UniFi Network Application是美国优比快(Ubiquiti)公司的一个网络管理软件,它允许用户通过一个集中的界面来管理网络中的各种设备,包括但不限于无线接入点(AP)、交换机、路由器等。 Ubiquiti Networks UniFi Network Application 9.1.120及之前版本存在安全漏洞,该漏洞源于配置不当的查询可能导致用户使用设备MAC地址进行身份验证。

Description (English)

The Ubiquiti Networks UNiFi Network Application is a network management software for Ubiquiti, which allows users to manage various devices in the network through a centralized interface, including but not limited to wireless access points (APs), switches, routers, etc. The Ubiquiti Networks UniFi Network Application 9.1.120 and previous versions had a security loophole, which stemmed from inappropriately configured queries that could lead to the user using the device MAC address for authentication.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

优比快

Published

2025-06-29

Last Modified

2026-02-24

References

https://nvd.nist.gov/vuln/detail/CVE-2025-24292 https://access.redhat.com/security/cve/cve-2025-24292

Patch

https://community.ui.com/releases/Security-Advisory-Bulletin-049-049/7a019b27-6c77-4500-bec8-596cd87c9292

Share on: