Loading
Generated remediation guidance and an executive summary. No account required.
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server certificates and keys.
Use CWE-862, Mbs-Solutions vendor hub and Universal Bacnet Router Firmware product page to widen CVE-2025-41765 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-41764, CVE-2025-41766 and CVE-2025-41758 for nearby disclosures in the same product family.