Unauthenticated Remote Attack Vulnerability in UBR by MBS Solutions
CVE-2025-41772

7.5HIGH

Key Information:

Vendor

Mbs

Vendor
CVE Published:
9 March 2026

What is CVE-2025-41772?

An unauthenticated remote attacker could exploit a vulnerability in UBR where session tokens are inadvertently exposed in plaintext through URL parameters of the wwwupdate.cgi endpoint. This exposure allows potential attackers to hijack valid sessions, leading to unauthorized access and manipulation of user accounts. It's crucial for administrators to ensure that all web endpoints are secured and to apply necessary updates to prevent such vulnerabilities.

Affected Version(s)

UBR-01 Mk II 0.0.0 < 6.0.1.0

UBR-02 0.0.0 < 6.0.1.0

UBR-LON 0.0.0 < 6.0.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
.