Use of GET request method with sensitive query strings (CWE-598) in the wwwupdate.cgi endpoint of the MBS Universal BACnet Router firmware before V6.0.1.0. Valid session tokens are passed as URL parameters in plaintext, where they may be logged by the browser, web server, or any intermediate proxy, leaked through the Referer header when off-site links are followed, or displayed on screen and bookmarked. An unauthenticated remote attacker can obtain these tokens and hijack active sessions. This vulnerability amplifies the impact of other flaws in the same advisory that require authenticated access.

MBS vendor advisory: MBS-2025-0001.