UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicious API request. This affects Cloud Key gen2 and Cloud Key gen2 Plus.
2020-04-13T14:15:12.167
2024-11-21T05:38:23.190
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ui | cloud_key_gen2 | ≤ 1.1.6 | Yes |
Operating System | ui | cloud_key_gen2_plus | ≤ 1.1.6 | Yes |