CVE-2025-41772 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint…
High CVSS: 7.5

CVE-2025-41772

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
Vendor
Mbs-solutions
Product
Universal Bacnet Router Firmware
CWE
CWE-598
Yayın Tarihi
2026-03-09 09:16:01
Güncelleme
2026-03-11 18:23:33
Source Identifier
info@cert.vde.com
KEV Date Added
-

Kategoriler

Referanslar