Описание
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.0.1.0 (исключая)
Одновременно
cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00326
Низкий
8.1 High
CVSS3
Дефекты
CWE-1242
Связанные уязвимости
CVSS3: 8.1
github
6 месяцев назад
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
EPSS
Процентиль: 25%
0.00326
Низкий
8.1 High
CVSS3
Дефекты
CWE-1242