Unauthenticated Remote Attack Vulnerability in UBR by MBS Solutions
CVE-2025-41772
7.5HIGH
What is CVE-2025-41772?
An unauthenticated remote attacker could exploit a vulnerability in UBR where session tokens are inadvertently exposed in plaintext through URL parameters of the wwwupdate.cgi endpoint. This exposure allows potential attackers to hijack valid sessions, leading to unauthorized access and manipulation of user accounts. It's crucial for administrators to ensure that all web endpoints are secured and to apply necessary updates to prevent such vulnerabilities.
Affected Version(s)
UBR-01 Mk II 0.0.0 < 6.0.1.0
UBR-02 0.0.0 < 6.0.1.0
UBR-LON 0.0.0 < 6.0.1.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
