Arbitrary Read with ubr-logread
CVE:
CVE-2025-41755
Product: Universal BACnet Routers (UBR)
Severity: Medium 5.7
Published: 28.11.2025
Advisory:
Read the advisory
An adversary can read any log file on the system by manipulating the logfile parameter in the ubr-logread method in wwwubr.cgi.
CWE: CWE-20:Improper Input Validation