CVE-2025-41762
6.2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.5 / Impact: 3.6
Source: info@cert.vde.com (Secondary)
Description
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.
Affected (1)
Products: Mbs Solutions: Universal Bacnet Router Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.1.0 |
| Running on/with | Platform Versions |
|---|---|
Mbs Solutions Ubr 01 Mk Ii | All versions |
Mbs Solutions Ubr 02 | All versions |
Mbs Solutions Ubr Lon | All versions |
References (1)
Timeline
No history available yet.