Jump to content

Unifi Protect showing notifications and devices of other users

cataSucc

Summary

 

A Reddit user, SandmaNn42, has reported being notified of a detection from Unifi protect camera that was not part of the users adopted cameras and in the notification showed a house that was not theirs. An additional user, turnerd10, in the comments reported opening the remote access page and seeing a UDM Pro that was not theirs. The Ubiquiti Reddit account has reached out to both users for more information.

zayr63jyc26c1.thumb.webp.1dadf429a7c9de13437f4df80db64f15.webp6b0ah4jyc26c1.thumb.webp.74488eeb3e519e87bddb106c7e0a36c3.webp

 

Quotes

Quote

Recently, my wife received a notification from UniFi Protect, which included an image from a security camera. However, here's the twist - this camera doesn't belong to us.

... we have two security cameras set up through UniFi Protect, and they've been working flawlessly until now. But this notification was completely out of the blue and showed footage from an unfamiliar camera. What's even more strange is that when my wife opened the Protect app immediately after receiving the notification, only our two cameras were listed, as usual.

 

My thoughts

I would disable remote access to your Unifi consoles until this is address by Ubiquiti. Its scary to think that someone could have access to someone else's network at random.

 

Sources

https://www.reddit.com/r/Ubiquiti/comments/18hgpw1/security_problem/

 

Link to comment
Share on other sites

Link to post
Share on other sites

And this is why you keep your NVR only locally accessible, if you want remote access use a split vpn........

Link to comment
Share on other sites

Link to post
Share on other sites

- Moved to Networking - 

 

Our tech news sub forum requires the sources to be from a legitimate news source

Community Standards || Tech News Posting Guidelines

---======================================================================---

CPU: R5 3600 || GPU: RTX 3070|| Memory: 32GB @ 3200 || Cooler: Scythe Big Shuriken || PSU: 650W EVGA GM || Case: NR200P

Link to comment
Share on other sites

Link to post
Share on other sites

On 12/13/2023 at 2:04 PM, Slottr said:

- Moved to Networking - 

 

Our tech news sub forum requires the sources to be from a legitimate news source

Does it get changed now that Unifi has verified what the Reddit user has said?

 

https://www.bleepingcomputer.com/news/security/ubiquiti-users-report-having-access-to-others-unifi-routers-cameras/

 

Because honestly moving it to networking has effectively torpedoed people seeing a pretty seriously issue...not to backseat mod as well, but multiple users all reporting the same issue at the same time doesn't count as a reputable source (when they are proving screen shots as well)

3735928559 - Beware of the dead beef

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, wanderingfool2 said:

Does it get changed now that Unifi has verified what the Reddit user has said?

Changes what? The alert is out. It's for Ubiquiti to address, not this forum.

 

5 hours ago, wanderingfool2 said:

Because honestly moving it to networking has effectively torpedoed people seeing a pretty seriously issue...not to backseat mod as well, but multiple users all reporting the same issue at the same time doesn't count as a reputable source (when they are proving screen shots as well)

I don't think anyone disagrees that this is a major issue. But, the LTT forum would be the last place to torpedo any Ubiquiti news, especially since other places with active monitors and more UniFi users that use Protect exist.

 

While I don't use Protect, I've noticed a couple of UniFi updates being pushed out over the last 3 days. Can't say that these updates are in response to the security concern; you can find that in the bugfix release notes.

Link to comment
Share on other sites

Link to post
Share on other sites

  • 1 month later...

Wondering if anyone has a solution for a local only deployment?

I've essentially setup home assistant to handle notifications for me at this point, but it would be great to use the normal protect app...

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×