CVE-2025-23123

CRITICAL

UniFi Protect Cameras <4.75.43 - RCE

Title source: llm
STIX 2.1

Description

A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a heap buffer overflow vulnerability in the UniFi Protect Cameras (Version 4.75.43 and earlier) firmware.

Scores

CVSS v3 10.0
EPSS 0.0168
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-122
Status published
Products (1)
Ubiquiti Inc/UniFi Protect Cameras 4.75.62
Published May 19, 2025
Tracked Since Feb 18, 2026