Ubiquiti UniFi Network
cpe:2.3:a:ui:unifi_network_application:*:*:*:*:*:*:*
- <= 9.1.120
A vulnerability exists in Ubiquiti UniFi Network application versions through 9.1.120, allowing users to authenticate to Enterprise WiFi or VPN services (L2TP and OpenVPN) using a device's MAC address from 802.1X or MAC Authentication. This issue arises if both services are enabled and share the same RADIUS profile.
Exploitation of this vulnerability could lead to unauthorized access to Enterprise WiFi or VPN services, allowing users to authenticate based on MAC address rather than proper credentials.
Users are advised to update the UniFi Network application to version 9.2.87 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.