7.5
CVE-2025-41772
- EPSS 0.05%
- Veröffentlicht 09.03.2026 08:18:49
- Zuletzt bearbeitet 11.03.2026 18:23:33
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mbs-solutions ≫ Universal Bacnet Router Firmware Version < 6.0.1.0
Mbs-solutions ≫ Ubr-01 Mk Ii Version-
Mbs-solutions ≫ Ubr-02 Version-
Mbs-solutions ≫ Ubr-lon Version-
Mbs-solutions ≫ Ubr-02 Version-
Mbs-solutions ≫ Ubr-lon Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.172 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-598 Use of GET Request Method With Sensitive Query Strings
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.