Ubiquiti UniFi IoT Doorlock Vulnerability Allows Unauthenticated Remote Unlock
What Happened — Security researcher Troy Hunt demonstrated that the UniFi IoT door‑lock can be unlocked remotely without authentication by exploiting a hard‑coded admin credential and an exposed local‑network API. The proof‑of‑concept shows a door can be opened from any device on the same LAN, and the flaw is present in all firmware versions shipped to date.
Why It Matters for Compliance & Audit Readiness
- The scenario is a textbook example of a control gap that SOC 2 Security and Availability criteria require you to detect, remediate, and retain evidence for.
- Continuous monitoring of device configurations and credential hygiene provides the audit‑ready evidence needed to demonstrate “least‑privilege” and “logical access” controls are in place.
- Verisq’s SOC2 Access Controls capability automates collection of configuration snapshots and credential rotation logs, giving you a defensible trail for auditors.
Who Is Affected — Smart‑home integrators, residential property managers, and any organization deploying Ubiquiti UniFi IoT door‑locks in corporate or multi‑tenant environments.
Recommended Actions
- Inventory all UniFi IoT door‑locks and verify firmware versions.
- Replace default credentials with unique, strong passwords and enforce MFA where possible.
- Segment IoT devices onto a dedicated VLAN and restrict inbound traffic to the management API.
- Enable continuous configuration monitoring and retain logs as SOC 2 evidence.
Source: Troy Hunt Weekly Update 518
Technical Notes
- Attack vector: Misconfiguration – hard‑coded admin password and unauthenticated API endpoint on the local network.
- Data types at risk: Physical access to premises; no personal data disclosed, but breach of physical security can lead to downstream data loss.
- Mitigation: Firmware update pending from Ubiquiti; until released, apply network segmentation and credential rotation.