CVE-2025-41762
—CVSS 3.1
6.2 medium
EPSS
<1%p0
Published
()
Modified
Description
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.
- Vendors
- mbs-solutions
- Products
- universal bacnet router firmware
- Weakness
- CWE-328
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.