Security Issue: Cloud Site Manager presented me your consoles, not mine

A severe bug in Ubiquiti’s cloud-based management platform briefly exposed some customers’ network consoles and camera feeds to other users, likely due to a misconfiguration or caching error in the cloud access layer. Commenters argue over whether Ubiquiti’s response and communication — including delayed status updates and reliance on private DMs — were adequate for an incident that could grant administrative control of third-party networks. The incident reignites broader concerns about mandatory cloud management for critical infrastructure, with many advocating self-hosted controllers, VPN-based access, or alternative vendors such as MikroTik, Aruba, or open source firewall solutions.

Incident and Impact

  • Users reported UniFi Cloud Site Manager showing other customers’ consoles and camera feeds instead of their own, with at least some reports of being able to perform configuration actions (e.g., VLAN creation).
  • Other reports suggested it might sometimes be “view only,” leading to debate whether this was purely a visual/caching issue or actual cross‑tenant access.
  • Several noted this is a critical class of failure: remote, centralized management incorrectly crossing tenant boundaries.

Cause and Technical Speculation

  • Multiple commenters speculated about a misconfigured CDN or cache layer (e.g., user/session tokens or user IDs cached incorrectly).
  • Others suggested an auth/session bug in the API layer, not just HTML caching.
  • Many emphasized that, from the outside, the exact root cause is unclear without a full postmortem.

Ubiquiti’s Response and Communication

  • Ubiquiti contacted the original reporter within about an hour and later published a “Bug-Fix Cloud Access Misconfiguration” statement.
  • Some felt this was a reasonable response time and appreciated the public acknowledgment.
  • Others criticized the lack of immediate status-page updates, broad customer notifications, or a detailed postmortem; some argued they should have temporarily disabled cloud remote access.
  • Counterargument: auto-shutting down cloud access on unverified reports could itself become a DoS vector.

Cloud, Security, and Status Pages

  • Strong criticism of tying security‑critical management to a proprietary cloud, especially with prior security controversies.
  • Some argued status pages should surface major security incidents; others warned that publicly flagging live vulnerabilities can increase risk before fixes are deployed.
  • Calls for end-to-end or at-rest encryption so misrouting data would at least be unreadable.

User Mitigations

  • Several advised disabling “Remote Access” on UniFi consoles and using VPN/WireGuard/Tailscale or similar for remote management instead.
  • Some run controllers locally (VM, Docker, or hardware keys) with outbound access heavily firewalled or blocked.
  • Others argued remote access via a third-party service always expands the attack surface, regardless of vendor.

Alternatives and Broader Ecosystem

  • Many users considered or recommended alternatives: MikroTik, Aruba/Aruba Instant On, TP-Link Omada, Ruckus, OpenWRT, OPNsense, pfSense, Firewalla, etc., each with trade‑offs in usability, cloud-dependence, and security record.
  • Ex‑employees and long‑time users described a perceived decline in Ubiquiti’s engineering focus and increasing emphasis on UX “polish,” cloud features, and prosumer marketing over core reliability and security.