
CVE-2025-41754 A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system. https://www.cve.org/CVERecord?id=CVE-2025-41754
Post summary
CVE‑2025‑41754 discloses a low‑privilege remote file‑read vulnerability via an undocumented ubr‑editfile API endpoint in wwwubr.cgi; no PoC, exploit, patch, or active exploitation reports are provided.


