CVE-2026-21635

An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:unifi_connect_ev_station_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:unifi_connect_ev_station_lite:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-05 17:15

Updated : 2026-01-30 01:22


NVD link : CVE-2026-21635

Mitre link : CVE-2026-21635

CVE.ORG link : CVE-2026-21635


JSON object : View

Products Affected

ui

  • unifi_connect_ev_station_lite
  • unifi_connect_ev_station_lite_firmware
CWE
CWE-284

Improper Access Control