Executive brief
Ubiquiti UniFi Protect Floodlight devices are smart lighting solutions integrated into security camera systems. A security flaw allows an unauthorized person on the same network to bypass folder restrictions and access internal system files. This could lead to the exposure of sensitive device information or configuration data.
Technical details
A path traversal vulnerability (CWE-22) exists in UniFi Protect Floodlight devices running firmware versions prior to 1.13.6. The flaw allows a remote, unauthenticated attacker with network access to the device to bypass directory restrictions. By sending specially crafted requests, an attacker can read sensitive files stored on the local file system. The vulnerability is rated high severity due to the lack of authentication required and the potential for full confidentiality impact on the device's data. Ubiquiti has released firmware version 1.13.6 to address this issue.
Affected products
- Ubiquiti Inc UniFi Protect Floodlight < 1.13.6
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory