Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-41756

Опубликовано: 09 мар. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*
Версия до 6.0.1.0 (исключая)

Одно из

cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00326
Низкий

8.1 High

CVSS3

Дефекты

CWE-1242

Связанные уязвимости

CVSS3: 8.1
github
6 месяцев назад

A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.

EPSS

Процентиль: 25%
0.00326
Низкий

8.1 High

CVSS3

Дефекты

CWE-1242