Critical Flaw in Ubiquiti UniFi Protect Cameras Allows Remote Takeover
By Netvora Tech News
A critical vulnerability has been discovered in Ubiquiti UniFi Protect cameras, allowing unauthorized attackers to take control of the devices remotely. The impact of the security flaw, rated 10.0 on a scale of 1 to 10, is significant, and Ubiquiti has released an update to fix the issue.
What is UniFi Protect?
UniFi Protect is a range of security cameras and models developed by Ubiquiti, a company known for its networking and surveillance equipment. The cameras are designed for indoor and outdoor use, and are popular among small businesses and homeowners.
The Vulnerability
The vulnerability, identified as CVE-2025-23123, is a heap buffer overflow that allows an attacker with access to the camera's management network to execute arbitrary code. This means that an attacker could potentially take control of the camera, access sensitive data, and even use the device for malicious purposes.
Impact and Mitigation
Ubiquiti has released a security bulletin urging users to update their cameras to version 4.75.62 or later to mitigate the vulnerability. The company rarely releases updates for vulnerabilities with an impact score of 10.0, making this a significant priority.
Other Similar Vulnerabilities
According to Ubiquiti's security bulletin, only four other security bulletins have contained vulnerabilities with an impact score of 10.0. This highlights the severity of the issue and the importance of prompt action to update affected devices.
- Users are advised to update their UniFi Protect cameras to the latest version as soon as possible.
- Administrators should ensure that all cameras on their network are updated to the latest version.
- Network administrators should monitor their networks for any signs of suspicious activity or unauthorized access.
Conclusion
The discovery of a critical vulnerability in Ubiquiti UniFi Protect cameras serves as a reminder of the importance of regular security updates and patching. Users and administrators should prioritize updating affected devices to ensure the security and integrity of their networks and devices.
Comments (0)
Leave a comment