CVE-2025-41762

An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.
References
Link Resource
https://www.mbs-solutions.de/mbs-2025-0001 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*

History

11 Mar 2026, 18:27

Type Values Removed Values Added
Summary
  • (es) Un atacante no autenticado puede abusar del hash débil de la copia de seguridad generada por el endpoint wwwdnload.cgi para obtener acceso no autorizado a datos sensibles, incluyendo hashes de contraseñas y certificados.
CPE cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*
cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*
References () https://www.mbs-solutions.de/mbs-2025-0001 - () https://www.mbs-solutions.de/mbs-2025-0001 - Vendor Advisory
First Time Mbs-solutions
Mbs-solutions ubr-lon
Mbs-solutions ubr-01 Mk Ii
Mbs-solutions ubr-02
Mbs-solutions universal Bacnet Router Firmware

09 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 09:16

Updated : 2026-03-11 18:27


NVD link : CVE-2025-41762

Mitre link : CVE-2025-41762

CVE.ORG link : CVE-2025-41762


JSON object : View

Products Affected

mbs-solutions

  • ubr-lon
  • ubr-02
  • universal_bacnet_router_firmware
  • ubr-01_mk_ii
CWE
CWE-328

Use of Weak Hash