CVE-2019-25651

HIGH

Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control

Title source: cna
STIX 2.1

Description

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices.

Scores

CVSS v3 8.3
EPSS 0.0008
EPSS Percentile 0.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-327
Status published
Products (8)
Ubiquiti/UniFi Network Controller < 5.10.12
Ubiquiti/UniFi Network Controller < 5.6.42
Ubiquiti/UniFi Network Controller 5.6.42
Ubiquiti/UniFi Network Controller 5.6.43 - 5.10.12
Ubiquiti/UniFi UAP Firmware < 4.0.6
Ubiquiti/UniFi UAP-AC Firmware < 3.8.17
Ubiquiti/UniFi USG Firmware < 4.4.34
Ubiquiti/UniFi USW Firmware < 4.0.6
Published Mar 27, 2026
Tracked Since Mar 29, 2026