← Vulnerability feed

Vulnerability record · CVE-2025-41766 · published 9 March 2026

CVE-2025-41766: Mbs-solutions universal bacnet router firmware out-of-bounds write vulnerability

Mbs Solutions · Universal Bacnet Router Firmware

A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.

8.8 CVSS 3.1 High EPSS 0.48% · top 60.9% CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-41766 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2025-41764Mbs-solutions universal bacnet router firmware missing authorization vulnerabilityDue to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u…EPSS 0.41%9.1CVE-2025-41765Mbs-solutions universal bacnet router firmware missing authorization vulnerabilityDue to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d…EPSS 0.27%8.8CVE-2025-41757Mbs-solutions universal bacnet router firmware path traversal vulnerabilityA low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not val…EPSS 0.54%8.8CVE-2025-41758Mbs-solutions universal bacnet router firmware path traversal vulnerabilityA low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead …EPSS 0.54%8.1CVE-2025-41756Mbs-solutions universal bacnet router firmware vulnerabilityA low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files …EPSS 0.33%7.8CVE-2025-41761Mbs-solutions universal bacnet router firmware argument injection vulnerabilityA low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. Thi…EPSS 0.16%7.5CVE-2025-41772Mbs-solutions universal bacnet router firmware vulnerabilityAn unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.c…EPSS 0.32%7.2CVE-2025-41767Mbs-solutions universal bacnet router firmware improper verification of cryptographic signature vulnerabilityA high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in …EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2025-41766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.