CVE-2019-25651 - Vulnerability Analysis
HighCVSS: 8.3Last Updated: March 27, 2026
Ubiquiti UniFi Network Controller - Weak Cryptography
Published: March 27, 2026Updated: March 27, 2026
Overview
Ubiquiti UniFi Network Controller < 5.10.12 (excluding 5.6.42) and various UAP, USW, USG firmware versions use AES-CBC encryption with cryptographic weaknesses, letting attackers with adjacent network access recover encryption keys and control devices.
Severity & Score
Severity: High
CVSS Score: 8.3
Impact
Attackers with adjacent network access can recover encryption keys, enabling unauthorized control and management of network devices.
Mitigation
Update to UniFi Network Controller version 5.10.12 or later and firmware versions 4.0.6 (UAP), 3.8.17 (UAP-AC Outdoor), 4.0.6 (USW), 4.4.34 (USG) or later.
References
Related Resources
Details
- CVE ID
- CVE-2019-25651
- Severity
- High
- CVSS Score
- 8.3
- Type
- weak_cryptography
- Status
- new
CWE
- CWE-327
CVSS Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H