CVE-2025-41767

HIGH

UBR - Privilege Escalation

Title source: llm

Description

A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in the web interface of UBR.

Scores

CVSS v3 7.2
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (1)
mbs-solutions/universal_bacnet_router_firmware < 6.0.1.0
Published Mar 09, 2026
Tracked Since Mar 09, 2026