ZeroHour

CVE-2025-41772

CVSS 3.1
7.5 high
EPSS
<1%p25
Published
()
Modified
Description

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.

Vendors
mbs-solutions
Products
universal bacnet router firmware
Weakness
CWE-598
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.