CVE-2025-41765: Unchecked role in wwwupload.cgi
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server certificates and keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41765?
The severity of CVE-2025-41765 is classified as high due to the potential for unauthorized data upload and manipulation.
How do I fix CVE-2025-41765?
To fix CVE-2025-41765, ensure that proper validation and authorization checks are enforced in the wwwupload.cgi endpoint.
What types of data can be exploited in CVE-2025-41765?
In CVE-2025-41765, an attacker can exploit the vulnerability to upload arbitrary data like contact images, HTTPS certificates, and system backups.
Which software is affected by CVE-2025-41765?
CVE-2025-41765 affects Mbs-solutions Universal Bacnet Router Firmware versions up to 6.0.1.0.
Can CVE-2025-41765 lead to remote code execution?
CVE-2025-41765 does not directly lead to remote code execution but allows unauthorized access to upload harmful data.