Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 9, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 9, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 9, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 9, 2025

      This Motorola Razr deal at Best Buy is the top offer I’ve seen on the flip phone

      May 9, 2025

      Google Maps can identify and save places in your screenshots – here’s how

      May 9, 2025

      T-Mobile is giving loyal users a free line right now – how to see if you qualify

      May 9, 2025

      CTA warns of tariff-fueled price hikes on consumer tech – but it’s not all bad news

      May 9, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Big Node, VS Code, and Mantine updates

      May 9, 2025
      Recent

      Big Node, VS Code, and Mantine updates

      May 9, 2025

      Prepare for Contact Center Week with Colleen Eager

      May 9, 2025

      Preparing for the Unthinkable: Safeguarding People and Productivity During India-Pakistan Conflicts

      May 9, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft confirms Offline Calendar for New Outlook on Windows 11

      May 9, 2025
      Recent

      Microsoft confirms Offline Calendar for New Outlook on Windows 11

      May 9, 2025

      Windows 11 Microsoft Store tests Copilot integration to increase app downloads

      May 9, 2025

      Beyond APT: Software Management with Flatpak on Ubuntu

      May 9, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»CVSS 10.0 Vulnerability Found in Ubiquity UniFi Protect Cameras

    CVSS 10.0 Vulnerability Found in Ubiquity UniFi Protect Cameras

    May 9, 2025

    CVE-2025-23123

    Ubiquity has disclosed two security vulnerabilities affecting its widely used video surveillance platform, UniFi Protect. One of the flaws, now assigned the identifier CVE-2025-23123, has been rated as critical with a maximum CVSS score of 10.0. Both issues have been addressed in recent firmware and application updates, and the company is urging users to install these patches without delay. 

    The vulnerabilities were detailed in Security Advisory Bulletin 047, published by Ubiquity on May 6, 2025. According to the bulletin, attackers who gain access to the management network of Ubiquity UniFi Protect systems could exploit the flaws to execute malicious code or maintain unauthorized access to video livestreams, even after links are supposedly disabled. 

    CVE-2025-23123: Critical Remote Code Execution Vulnerability 

    CVE-2025-23123

    The more severe of the two issues, CVE-2025-23123, affects UniFi Protect Cameras running firmware version 4.75.43 and earlier. This vulnerability allows a remote attacker with internal network access to trigger a heap-based buffer overflow, enabling the execution of arbitrary code. The flaw is classified as a Remote Code Execution (RCE) threat and poses cybersecurity risks for enterprise environments. 

    “This vulnerability is especially dangerous because of its low complexity and the absence of user interaction needed to exploit it,” Ubiquity noted.

    The CVSS v3.0 vector for this flaw is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, which confirms that the vulnerability can be exploited over the network without authentication or user intervention. 

    Persistent Livestream Access 

    The second vulnerability, identified as CVE-2025-23164, affects the Ubiquity UniFi Protect Application version 5.3.41 and earlier. This flaw stems from a misconfigured access token mechanism, which could allow a user to retain access to a livestream after the original “Share Livestream” link has been disabled.  

    Though this vulnerability is rated as medium with a CVSS score of 4.4, it still poses privacy and surveillance concerns, especially for users sharing security camera access. Ubiquity attributes this discovery to security researcher Mike S. Schonert and has resolved the issue in version 5.3.45 of the UniFi Protect application. 

    Updates and Fixes Released 

    To address these vulnerabilities, Ubiquity has released the following updates: 

    • UniFi Protect Cameras 4.75.62: This update resolves the critical RCE issue and includes performance enhancements like improved Talk Back resiliency and more accurate vehicle detection for G6 models. A bug causing failure in spotlight activation after target detection was also fixed. 
    • UniFi Protect Application 5.3.45: Alongside the security patch, this version includes improvements to cloud archiving UX, doorbell volume controls, and a bug fix for incorrect camera reassignment following an AI port restart. 

    Despite these improvements, Ubiquity did note a known issue: Hallway mode streaming in HDR-disabled settings is currently not functioning on G5-Pro models. 

    Users are strongly urged to update their Ubiquity UniFi systems immediately, as unpatched devices—especially those on exposed or partially secured networks—can be exploited through critical vulnerabilities like this one, potentially allowing attackers to install malware, conduct unauthorized surveillance, or access broader network resources.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleGoogle Expands On-Device AI to Counter Evolving Online Scams
    Next Article Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 10, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4496 – TOTOLINK CloudACMunualUpdate Buffer Overflow Vulnerability

    May 10, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Design in Motion: The Animation Principles Behind Green Stack

    News & Updates

    The best Prime Day 2024 tablet deals

    Development

    You can get a free $349 Starlink kit if you live in one of these US states

    News & Updates

    CVE-2025-43961 – Fujifilm LibRaw Out-of-Bounds Read Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    aidesk.pro

    December 26, 2024

    Post Content Source: Read More 

    I tested MSI Claw 8 AI+ and compared it against Steam Deck — Here’s why one of these handhelds reigns supreme

    March 23, 2025

    Create a custom JavaScript sparkle cursor

    April 17, 2025

    Ghostty: New Open Source Terminal That’s Spookily Good

    December 29, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.