6.5
CVE-2025-41763
- EPSS 0.01%
- Veröffentlicht 09.03.2026 08:17:36
- Zuletzt bearbeitet 11.03.2026 18:27:25
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, including system backups and certificate request files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mbs-solutions ≫ Universal Bacnet Router Firmware Version < 6.0.1.0
Mbs-solutions ≫ Ubr-01 Mk Ii Version-
Mbs-solutions ≫ Ubr-02 Version-
Mbs-solutions ≫ Ubr-lon Version-
Mbs-solutions ≫ Ubr-02 Version-
Mbs-solutions ≫ Ubr-lon Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.021 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.