CVE-2025-41772
HIGHUBR - Info Disclosure
Title source: llmDescription
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
References (1)
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
17.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-598
Status
published
Products (1)
mbs-solutions/universal_bacnet_router_firmware
< 6.0.1.0
Published
Mar 09, 2026
Tracked Since
Mar 09, 2026