CVE-2025-41763
MEDIUMwwwdnload.cgi - Info Disclosure
Title source: llmDescription
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, including system backups and certificate request files.
References (1)
Scores
CVSS v3
6.5
EPSS
0.0002
EPSS Percentile
6.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-497
Status
draft
Timeline
Published
Mar 09, 2026
Tracked Since
Mar 09, 2026