High
CVE-2025-41766
A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr…
High
CVE-2025-41767
A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in…
Medium
CVE-2025-41760
An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an…
High
CVE-2025-41761
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to o…
Medium
CVE-2025-41762
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauth…
Medium
CVE-2025-41763
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl…