Loading
Generated remediation guidance and an executive summary. No account required.
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
Use CWE-598, Mbs-Solutions vendor hub and Universal Bacnet Router Firmware product page to widen CVE-2025-41772 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-41765, CVE-2025-41764 and CVE-2025-41766 for nearby disclosures in the same product family.