CVE-2025-41756: Arbitrary Write with ubr-editfile
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41756?
CVE-2025-41756 is considered to have a high severity due to the potential for remote attackers to write arbitrary files on the affected system.
How do I fix CVE-2025-41756?
To mitigate CVE-2025-41756, it is recommended to update to the latest version of the Universal Bacnet Router Firmware, specifically versions above 6.0.1.0.
Which products are affected by CVE-2025-41756?
CVE-2025-41756 affects Mbs-solutions Universal Bacnet Router Firmware versions prior to 6.0.1.0.
Can CVE-2025-41756 be exploited remotely?
Yes, CVE-2025-41756 can be exploited remotely by a low-privileged attacker through the ubr-editfile method in wwwubr.cgi.
What type of vulnerability is CVE-2025-41756?
CVE-2025-41756 is classified as an arbitrary write vulnerability, allowing file manipulation on the system.