A misconfigured query in UniFi Network (v9.1.120 and...
Moderate severity
Unreviewed
Published
Jun 29, 2025
to the GitHub Advisory Database
•
Updated Jun 30, 2025
Description
Published by the National Vulnerability Database
Jun 29, 2025
Published to the GitHub Advisory Database
Jun 29, 2025
Last updated
Jun 30, 2025
A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.
References