Session Management Vulnerability
CVE:
CVE-2025-41763
Product: Universal BACnet Routers (UBR)
Severity: Low 3.5
Published: 28.11.2025
Advisory:
Read the advisory
Guest accounts can download restricted content by directly interacting with the wwwdnload.cgi endpoint, which only checks if a session exists but not the role associated with it.
CWE: CWE-269:Improper Privilege Management