CVE-2025-41761: Privilege escalation possible
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41761?
CVE-2025-41761 is considered a low-severity vulnerability that allows privilege escalation for local attackers.
How do I fix CVE-2025-41761?
To mitigate CVE-2025-41761, restrict the permissions of the UBR service account to prevent unprivileged users from executing binaries with sudo.
Who is affected by CVE-2025-41761?
CVE-2025-41761 affects users of the Universal Bacnet Router Firmware versions up to 6.0.1.0.
What could an attacker gain from exploiting CVE-2025-41761?
An attacker exploiting CVE-2025-41761 can escalate privileges to achieve full system access on the targeted system.
What software is vulnerable in CVE-2025-41761?
CVE-2025-41761 specifically affects the Mbs-solutions Universal Bacnet Router Firmware prior to version 6.0.1.0.