CVE-2025-41762: Secret leak with wwwdnload.cgi
Published Mar 9, 2026
·Updated
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.
Affected Software
4 affected components
All of the following
Mbs-solutions Universal Bacnet Router Firmware<6.0.1.0
Any of the following
Mbs-solutions Ubr-01 Mk Ii
Mbs-solutions Ubr-02
Mbs-solutions Ubr-lon
Event History
Mar 9, 2026
CVE Published
via MITRE·08:17 AM
Data Sourced
via MITRE·08:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41762?
CVE-2025-41762 is considered a high severity vulnerability due to the potential unauthorized access to sensitive data.
2
How do I fix CVE-2025-41762?
To remediate CVE-2025-41762, it is advised to update to a firmware version that addresses the vulnerability, specifically above 6.0.1.0.
3
Who is affected by CVE-2025-41762?
CVE-2025-41762 affects users of the Mbs-solutions Universal Bacnet Router Firmware version up to 6.0.1.0.
4
What data can be exposed due to CVE-2025-41762?
CVE-2025-41762 can lead to the exposure of sensitive data, including password hashes and certificates.
5
Is authentication required to exploit CVE-2025-41762?
No, CVE-2025-41762 can be exploited by unauthenticated attackers.