<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2019-25652 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2019-25652/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 27 Mar 2026 22:16:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2019-25652/feed.xml" rel="self" type="application/rss+xml"/><item><title>UniFi Network Controller Improper Certificate Verification Vulnerability (CVE-2019-25652)</title><link>https://feed.craftedsignal.io/briefs/2026-03-unifi-cert-bypass/</link><pubDate>Fri, 27 Mar 2026 22:16:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-unifi-cert-bypass/</guid><description>UniFi Network Controller versions before 5.10.22 and 5.11.x before 5.11.18 contain an improper certificate verification vulnerability, enabling adjacent network attackers to perform man-in-the-middle attacks by presenting a fraudulent SSL certificate during SMTP connections to intercept traffic and steal credentials.</description><content:encoded>&lt;p>CVE-2019-25652 affects UniFi Network Controller versions prior to 5.10.22 and 5.11.x before 5.11.18. The vulnerability stems from an improper certificate verification process during SMTP connections. An attacker positioned on an adjacent network can exploit this weakness to conduct man-in-the-middle (MitM) attacks. By presenting a false SSL certificate, the attacker can intercept SMTP traffic intended for the UniFi Network Controller, potentially gaining access to sensitive information…&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>unifi</category><category>mitm</category><category>credential-theft</category><category>cve-2019-25652</category></item></channel></rss>