Unauthorized File Access Vulnerability in BACnet Devices
CVE-2025-41753
9.3CRITICAL
What is CVE-2025-41753?
This vulnerability arises from inadequate validation of dynamically created BACnet File Object names, allowing an unauthenticated remote attacker to exploit this weakness. The attacker is able to manipulate file paths, resulting in the potential for unauthorized access to arbitrary files outside the intended directory. This misconfiguration may lead to the reading or overwriting of sensitive files, leaving systems vulnerable and ultimately enabling full compromise of affected devices.
Affected Version(s)
0750-811x-xxxx-xxxx 1.0.0 < 4.8.9
0750-811x-xxxx-xxxx 1.0.0 < 4.8.9 (70)
0750-821x-xxx-xxx 1.0.0 < 4.8.9
