{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-27212",
        "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
        "state": "PUBLISHED",
        "assignerShortName": "hackerone",
        "dateReserved": "2025-02-20T01:00:01.799Z",
        "datePublished": "2025-08-04T22:12:18.820Z",
        "dateUpdated": "2025-08-05T13:33:09.184Z"
    },
    "containers": {
        "cna": {
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network.\r\n\r\n \r\n\r\nAffected Products:\r\nUniFi Access Reader Pro (Version 2.14.21 and earlier)\r\nUniFi Access G2 Reader Pro (Version 1.10.32 and earlier)\r\nUniFi Access G3 Reader Pro (Version 1.10.30 and earlier)\r\nUniFi Access Intercom (Version 1.7.28 and earlier)\r\nUniFi Access G3 Intercom (Version 1.7.29 and earlier)\r\nUniFi Access Intercom Viewer (Version 1.3.20 and earlier)\r\n\r\n \r\n\r\nMitigation:\r\nUpdate UniFi Access Reader Pro Version 2.15.9 or later\r\nUpdate UniFi Access G2 Reader Pro Version 1.11.23 or later\r\nUpdate UniFi Access G3 Reader Pro Version 1.11.22 or later\r\nUpdate UniFi Access Intercom Version 1.8.22 or later\r\nUpdate UniFi Access G3 Intercom Version 1.8.22 or later\r\nUpdate UniFi Access Intercom Viewer Version 1.4.39 or later"
                }
            ],
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "vendor": "Ubiquiti Inc",
                    "product": "UniFi Access Reader Pro",
                    "versions": [
                        {
                            "version": "2.15.9",
                            "status": "affected",
                            "lessThan": "2.15.9",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "vendor": "Ubiquiti Inc",
                    "product": "UniFi Access G2 Reader Pro",
                    "versions": [
                        {
                            "version": "1.11.23",
                            "status": "affected",
                            "lessThan": "1.11.23",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "vendor": "Ubiquiti Inc",
                    "product": "UniFi Access G3 Reader Pro",
                    "versions": [
                        {
                            "version": "1.11.22",
                            "status": "affected",
                            "lessThan": "1.11.22",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "vendor": "Ubiquiti Inc",
                    "product": "UniFi Access Intercom",
                    "versions": [
                        {
                            "version": "1.8.22",
                            "status": "affected",
                            "lessThan": "1.8.22",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "vendor": "Ubiquiti Inc",
                    "product": "UniFi Access G3 Intercom",
                    "versions": [
                        {
                            "version": "1.8.22",
                            "status": "affected",
                            "lessThan": "1.8.22",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "defaultStatus": "unaffected",
                    "vendor": "Ubiquiti Inc",
                    "product": "UniFi Access Intercom Viewer",
                    "versions": [
                        {
                            "version": "1.4.39",
                            "status": "affected",
                            "lessThan": "1.4.39",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-051-051/583fa6e1-3d85-42ec-a453-651d1653c9b3"
                }
            ],
            "providerMetadata": {
                "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1",
                "shortName": "hackerone",
                "dateUpdated": "2025-08-04T22:12:18.820Z"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-20",
                                "lang": "en",
                                "description": "CWE-20 Improper Input Validation"
                            }
                        ]
                    },
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-77",
                                "lang": "en",
                                "description": "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 9.8,
                            "attackVector": "NETWORK",
                            "baseSeverity": "CRITICAL",
                            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "NONE",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-08-05T13:29:55.643740Z",
                                "id": "CVE-2025-27212",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-08-05T13:33:09.184Z"
                }
            }
        ]
    }
}