Home

Description

A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.

PUBLISHED Reserved 2025-01-17 | Published 2025-06-29 | Updated 2025-06-30 | Assigner hackerone




MEDIUM: 6.8CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Product status

Default status
unaffected

9.2.87 (semver) before 9.2.87
affected

References

community.ui.com/...049/7a019b27-6c77-4500-bec8-596cd87c9292

cve.org (CVE-2025-24292)

nvd.nist.gov (CVE-2025-24292)

Download JSON