logo

Hacking Unifi Controller Passwords for Fun and WIFI

ID: 5a28e8bb-2403-5ffb-aa5b-0b1b2fd7ffb9

STIX ID: report--5a28e8bb-2403-5ffb-aa5b-0b1b2fd7ffb9

Feed Name: Black Hills Infosec Blog

Date Published: 2021-10-21

Date Updated: 2026-04-27

Author: BHIS

...
...

This post demonstrates a post-compromise technique against Ubiquiti UniFi Controller installations: by accessing the unauthenticated MongoDB bound to localhost, an attacker can retrieve the admin’s SHA512-crypt hash, crack or overwrite it to gain controller access, and extract sensitive data (e.g., WLAN PSKs, device auth, cloud/API credentials). The author stresses that compromise of the controller host equals compromise of the network, urges proper hardening and dedicated hosting (not a forgotten laptop), and notes that while this behavior is by design, it poses significant risk if the underlying system is not secured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.