CVE-2025-41758: Arbitrary Write with wwwupload.cgi
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41758?
CVE-2025-41758 is categorized as a high-severity vulnerability due to its potential for full system compromise.
How do I fix CVE-2025-41758?
To fix CVE-2025-41758, update the affected Mbs-solutions Universal Bacnet Router Firmware to version 6.0.1.0 or later.
What systems are affected by CVE-2025-41758?
CVE-2025-41758 affects Mbs-solutions Universal Bacnet Router Firmware versions prior to 6.0.1.0.
Can CVE-2025-41758 be exploited remotely?
Yes, CVE-2025-41758 can be exploited by a low-privileged remote attacker via the wwupload.cgi endpoint.
What are the risks associated with CVE-2025-41758?
The risks associated with CVE-2025-41758 include unauthorized file overwriting and the potential for full system compromise.