Network Access Control Flaw in MBS Solutions Products
CVE-2025-41759
4.9MEDIUM
What is CVE-2025-41759?
A flaw in MBS Solutions' network security products allows administrators to incorrectly configure network access by using unsupported values like '*' or 'all' as network identifiers. Instead of triggering a validation error, these values are silently interpreted as network 0, which results in a failure to block any networks. This misconfiguration may leave systems exposed to unauthorized access, highlighting the need for vigilant network access control practices.
Affected Version(s)
UBR-01 Mk II 0.0.0 < 6.0.1.0
UBR-02 0.0.0 < 6.0.1.0
UBR-LON 0.0.0 < 6.0.1.0
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
