CVE-2025-24292

A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.
Configurations

No configuration.

History

30 Jun 2025, 14:15

Type Values Removed Values Added
CWE CWE-287
Summary
  • (es) Una consulta mal configurada en UniFi Network (v9.1.120 y anteriores) podría permitir que los usuarios se autentiquen en Enterprise WiFi o VPN Server (l2tp y OpenVPN) utilizando la dirección MAC de un dispositivo de 802.1X o autenticación MAC, si ambos servicios están habilitados y comparten el mismo perfil RADIUS.

29 Jun 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-29 20:15

Updated : 2025-06-30 18:38


NVD link : CVE-2025-24292

Mitre link : CVE-2025-24292

CVE.ORG link : CVE-2025-24292


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication