Ui Unifi Network Controller
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Ui Unifi Network Controller.
By the Year
In 2026 there have been 2 vulnerabilities in Ui Unifi Network Controller with an average score of 7.9 out of ten. Unifi Network Controller did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 7.90 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 9.80 |
It may take a day or so for new Unifi Network Controller vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Ui Unifi Network Controller Security Vulnerabilities
UniFi Network Controller <5.10.22/5.11.18: Improper Cert Verification in SMTP
CVE-2019-25652
7.5 - High
- March 27, 2026
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and obtain credentials by exploiting the insecure SSL host verification mechanism in the SMTP certificate validation process.
Improper Certificate Validation
AES-CBC Weakness Enables Key Recovery in Ubiquiti UniFi Controller <5.10.12
CVE-2019-25651
8.3 - High
- March 27, 2026
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices.
Use of a Broken or Risky Cryptographic Algorithm
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228)
CVE-2021-44530
9.8 - Critical
- January 14, 2022
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.
Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Ui Unifi Network Controller or by Ui? Click the Watch button to subscribe.