HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2019-25652 — UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contai...
Friday, March 27, 2026 at 10:16 PM UTC·Source: NIST NVD
Updated: Thursday, April 2, 2026 at 05:46 PM UTC
Executive Summary
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and obtain credentials by exploiting the insecure SSL host verification mechanism in the S
Analysis
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and obtain credentials by exploiting the insecure SSL host verification mechanism in the SMTP certificate validation process.
CVSS Score: 7.5. Published: 2026-03-27T22:16:19.380.