Arbitrary Write with ubr-editfile
CVE:
CVE-2025-41756
Product: Universal BACnet Routers (UBR)
Severity: High 8.0
Published: 28.11.2025
Advisory:
Read the advisory
An attacker can write to any file on the system through the ubr-editfile method in wwwubr.cgi, which is an unused undocumented API endpoint.
CWE: CWE-912:Hidden Functionality