CVE-2025-66269

HIGH

UPSilon 2000 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in

Scores

CVSS v4 7.1
EPSS 0.0002
EPSS Percentile 3.6%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-428
Status published
Products (1)
MegaTec Taiwan/UPSilon2000V6.0 6.0.5
Published Nov 26, 2025
Tracked Since Feb 18, 2026