A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API.
Affected Products:
UniFi Talk Touch (Version 1.21.16 and earlier)
UniFi Talk Touch Max (Version 2.21.22 and earlier)
UniFi Talk G3 Phones (Version 3.21.26 and earlier)
Mitigation:
Update the UniFi Talk Touch to Version 1.21.17 or later.
Update the UniFi Talk Touch Max to Version 2.21.23 or later.
Update the UniFi Talk G3 Phones to Version 3.21.27 or later.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ui
Ui unifi Os Ui unifi Talk |
|
| Vendors & Products |
Ui
Ui unifi Os Ui unifi Talk |
Thu, 30 Oct 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Products: UniFi Talk Touch (Version 1.21.16 and earlier) UniFi Talk Touch Max (Version 2.21.22 and earlier) UniFi Talk G3 Phones (Version 3.21.26 and earlier) Mitigation: Update the UniFi Talk Touch to Version 1.21.17 or later. Update the UniFi Talk Touch Max to Version 2.21.23 or later. Update the UniFi Talk G3 Phones to Version 3.21.27 or later. | |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published: 2025-10-30T23:30:28.298Z
Updated: 2025-11-03T15:36:24.687Z
Reserved: 2025-06-18T15:00:00.895Z
Link: CVE-2025-52663
Updated: 2025-11-03T15:36:06.812Z
Status : Awaiting Analysis
Published: 2025-10-31T00:15:36.773
Modified: 2025-11-04T15:41:56.843
Link: CVE-2025-52663
No data.
ReportizFlow