๐Ÿ” CVE Alert

CVE-2019-25651

HIGH 8.3

Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
1th

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices.

CWE CWE-327
Vendor ubiquiti
Product unifi network controller
Published Mar 27, 2026
Last Updated Mar 30, 2026
Stay Ahead of the Next One

Get instant alerts for ubiquiti unifi network controller

Be the first to know when new high vulnerabilities affecting ubiquiti unifi network controller are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Ubiquiti / UniFi Network Controller
0 < 5.10.12
Ubiquiti / UniFi UAP Firmware
0 < 4.0.6
Ubiquiti / UniFi UAP-AC Firmware
0 < 3.8.17
Ubiquiti / UniFi USW Firmware
0 < 4.0.6
Ubiquiti / UniFi USG Firmware
0 < 4.4.34

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
community.ui.com: https://community.ui.com/releases/Security-Advisory-Bulletin-004-004/462e561b-9efd-4c23-bfa7-53d59cc64ecb vulncheck.com: https://www.vulncheck.com/advisories/ubiquiti-unifi-devices-use-of-aes-cbc-allows-key-recovery-and-unauthorized-device-control