CVE-2025-41765

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server certificates and keys.
References
Link Resource
https://www.mbs-solutions.de/mbs-2025-0001 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*

History

11 Mar 2026, 18:27

Type Values Removed Values Added
Summary
  • (es) Debido a una aplicación de autorización insuficiente, un atacante remoto no autorizado puede explotar el endpoint wwwupload.cgi para cargar y aplicar datos arbitrarios. Esto incluye, pero no se limita a, imágenes de contacto, certificados HTTPS, copias de seguridad del sistema para restauración, configuraciones de pares de servidor, y certificados y claves de servidor BACnet/SC.
CPE cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*
cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*
cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*
References () https://www.mbs-solutions.de/mbs-2025-0001 - () https://www.mbs-solutions.de/mbs-2025-0001 - Vendor Advisory
First Time Mbs-solutions
Mbs-solutions ubr-lon
Mbs-solutions ubr-01 Mk Ii
Mbs-solutions ubr-02
Mbs-solutions universal Bacnet Router Firmware

09 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 09:16

Updated : 2026-03-11 18:27


NVD link : CVE-2025-41765

Mitre link : CVE-2025-41765

CVE.ORG link : CVE-2025-41765


JSON object : View

Products Affected

mbs-solutions

  • ubr-lon
  • ubr-02
  • universal_bacnet_router_firmware
  • ubr-01_mk_ii
CWE
CWE-862

Missing Authorization