Update Push Vulnerability
CVE:
CVE-2025-41764
Product: Universal BACnet Routers (UBR)
Severity: High 8.0
Published: 28.11.2025
Advisory:
Read the advisory
Guest accounts can push updates by directly interacting with the wwwupdate.cgi endpoint, which only checks if a session exists but not the role associated with it.
CWE: CWE-269:Improper Privilege Management