Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.mbs-solutions.de/mbs-2025-0001 |
|
Wed, 11 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mbs-solutions
Mbs-solutions ubr-01 Mk Ii Mbs-solutions ubr-02 Mbs-solutions ubr-lon Mbs-solutions universal Bacnet Router Firmware |
|
| CPEs | cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:* cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:* cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:* cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mbs-solutions
Mbs-solutions ubr-01 Mk Ii Mbs-solutions ubr-02 Mbs-solutions ubr-lon Mbs-solutions universal Bacnet Router Firmware |
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mbs
Mbs ubr-01 Mk Ii Mbs ubr-02 Mbs ubr-lon |
|
| Vendors & Products |
Mbs
Mbs ubr-01 Mk Ii Mbs ubr-02 Mbs ubr-lon |
Mon, 09 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR. | |
| Title | wwwupdate.cgi Session token in URL | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-03-09T18:18:41.648Z
Reserved: 2025-04-16T11:18:45.761Z
Link: CVE-2025-41772
Updated: 2026-03-09T18:18:29.921Z
Status : Analyzed
Published: 2026-03-09T09:16:01.537
Modified: 2026-03-11T18:23:33.280
Link: CVE-2025-41772
No data.
OpenCVE Enrichment
Updated: 2026-03-10T14:09:57Z