CVE-2025-41757 Details
Description
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.
A vulnerability exists in the backup restore functionality of the MBS Universal BACnet Router (UBR) firmware. This issue allows low-privileged remote attackers to overwrite or create arbitrary files on the system. The vulnerability arises because the restore function, which operates with elevated privileges, fails to validate the contents of the backup archive before applying it. As a result, attackers can exploit this oversight to manipulate files anywhere on the device.
Users are advised to update to the new UBR firmware version 6.0.1.0, which addresses this vulnerability. For more details, please check the release notes on the MBS Solutions website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.mbs-solutions.de/mbs-2025-0001 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mbs-solutions universal bacnet router firmware | < 6.0.1.0 |
CPE
Remediation
| |
| mbs-solutions ubr-01 mk ii | All versions |
CPE
Remediation
| |
| mbs-solutions ubr-02 | All versions |
CPE
Remediation
| |
| mbs-solutions ubr-lon | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 9, 2026 | New CVE Received | [email protected] |