CVE-2025-27215

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system. Affected Products: UniFi Connect Display Cast (Version 1.10.3 and earlier) UniFi Connect Display Cast Pro (Version 1.0.89 and earlier) UniFi Connect Display Cast Lite (Version 1.0.3 and earlier) Mitigation: Update UniFi Connect Display Cast to Version 1.10.7 or later Update UniFi Connect Display Cast Pro to Version 1.0.94 or later Update UniFi Connect Display Cast Lite to Version 1.1.8 or later
Configurations

No configuration.

History

21 Aug 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-284
Summary
  • (es) Un control de acceso inadecuado podría permitir que un agente malicioso autenticado en la API de ciertos dispositivos UniFi Connect Display Cast realice cambios no compatibles en el sistema. Productos afectados: UniFi Connect Display Cast (versión 1.10.3 y anteriores), UniFi Connect Display Cast Pro (versión 1.0.89 y anteriores), UniFi Connect Display Cast Lite (versión 1.0.3 y anteriores). Mitigación: Actualizar UniFi Connect Display Cast a la versión 1.10.7 o posterior. Actualizar UniFi Connect Display Cast Pro a la versión 1.0.94 o posterior. Actualizar UniFi Connect Display Cast Lite a la versión 1.1.8 o posterior.

21 Aug 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 01:15

Updated : 2025-08-22 18:09


NVD link : CVE-2025-27215

Mitre link : CVE-2025-27215

CVE.ORG link : CVE-2025-27215


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control