CVE-2025-41772 Details
Description
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
A vulnerability exists in the MBS Universal BACnet Router's web interface, specifically within the wwwupdate.cgi endpoint. Unauthenticated remote attackers can access valid session tokens, which are transmitted in plaintext via URL parameters. This exposure increases the risk of session token interception, potentially allowing unauthorized access to user accounts. The vulnerability affects all UBR firmware versions prior to 6.0.1.0.
Users are advised to update to the latest UBR firmware version 6.0.1.0, which addresses this vulnerability. For more details, please check the release notes on the MBS Solutions website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.mbs-solutions.de/mbs-2025-0001 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-598 | Use of GET Request Method With Sensitive Query Strings | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mbs-solutions universal bacnet router firmware | < 6.0.1.0 |
CPE
Remediation
| |
| mbs-solutions ubr-01 mk ii | All versions |
CPE
Remediation
| |
| mbs-solutions ubr-02 | All versions |
CPE
Remediation
| |
| mbs-solutions ubr-lon | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 9, 2026 | New CVE Received | [email protected] |