ZeroHour

CVE-2025-41761

CVSS 3.1
7.8 high
EPSS
<1%p6
Published
()
Modified
Description

A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.

Vendors
mbs-solutions
Products
universal bacnet router firmware
Weakness
CWE-88
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.