CVE-2025-41765
CRITICALwwwupload.cgi - Auth Bypass
Title source: llmDescription
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server certificates and keys.
References (1)
Scores
CVSS v3
9.1
EPSS
0.0006
EPSS Percentile
18.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Classification
CWE
CWE-862
Status
draft
Timeline
Published
Mar 09, 2026
Tracked Since
Mar 09, 2026