Unifi Network Controller Ui Unifi Network Controller

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Ui Unifi Network Controller.

By the Year

In 2026 there have been 2 vulnerabilities in Ui Unifi Network Controller with an average score of 7.9 out of ten. Unifi Network Controller did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 2 7.90
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 1 9.80

It may take a day or so for new Unifi Network Controller vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Ui Unifi Network Controller Security Vulnerabilities

UniFi Network Controller <5.10.22/5.11.18: Improper Cert Verification in SMTP
CVE-2019-25652 7.5 - High - March 27, 2026

UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and obtain credentials by exploiting the insecure SSL host verification mechanism in the SMTP certificate validation process.

Improper Certificate Validation

AES-CBC Weakness Enables Key Recovery in Ubiquiti UniFi Controller <5.10.12
CVE-2019-25651 8.3 - High - March 27, 2026

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices.

Use of a Broken or Risky Cryptographic Algorithm

An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228)
CVE-2021-44530 9.8 - Critical - January 14, 2022

An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.

Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Ui Unifi Network Controller or by Ui? Click the Watch button to subscribe.

Ui
Vendor

subscribe