Home

Description

A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share Livestream" link to maintain access to the corresponding livestream subsequent to such link becoming disabled.

PUBLISHED Reserved 2025-01-12 | Published 2025-05-19 | Updated 2025-05-19 | Assigner hackerone




MEDIUM: 4.4CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Product status

Default status
unaffected

5.3.45 (semver) before 5.3.45
affected

References

community.ui.com/...047/cef86c37-7421-44fd-b251-84e76475a5bc

cve.org (CVE-2025-23164)

nvd.nist.gov (CVE-2025-23164)

Download JSON