CVE-2025-41766: Stack buffer overflow on parsing web request
Published Mar 9, 2026
·Updated
A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.
Affected Software
4 affected components
All of the following
Mbs-solutions Universal Bacnet Router Firmware<6.0.1.0
Any of the following
Mbs-solutions Ubr-01 Mk Ii
Mbs-solutions Ubr-02
Mbs-solutions Ubr-lon
Event History
Mar 9, 2026
CVE Published
via MITRE·08:18 AM
Data Sourced
via MITRE·08:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41766?
CVE-2025-41766 has a high severity level due to the potential for full device compromise via a stack buffer overflow.
2
How do I fix CVE-2025-41766?
To fix CVE-2025-41766, upgrade the Universal Bacnet Router firmware to version 6.0.1.0 or later.
3
Who is affected by CVE-2025-41766?
CVE-2025-41766 affects users of the Universal Bacnet Router firmware versions prior to 6.0.1.0.
4
What type of attack does CVE-2025-41766 describe?
CVE-2025-41766 describes a remote code execution vulnerability through a crafted HTTP POST request.
5
Can CVE-2025-41766 be exploited by unauthenticated users?
Yes, CVE-2025-41766 can be exploited by low-privileged remote attackers without authentication.