CVE-2025-41757Disclosure(mbs-solutions / ubr-01_mk_ii)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Prioritize remediation for mbs-solutions ubr-01_mk_ii systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ubr-01_mk_ii
  • ubr-02
  • ubr-lon
  • universal_bacnet_router_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-09); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Products
ubr-01_mk_iiubr-02ubr-lonuniversal_bacnet_router_firmware

1 version affected across 4 products

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-09: 5Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Active Exploitation · 2026-03-09: 1Technical Details · 2026-03-09: 4Technical Details · 2026-03-12: 103-0903-1003-12
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-095
Active Exploitation1Disclosure3General1
2026-03-101
Disclosure1
2026-03-121
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-41757 (CVSS:8.8, HIGH) is Analyzed. A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevate..https://nvd.nist.gov/vuln/detail/CVE-2025-41757 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post provides a basic disclosure of CVE‑2025‑41757, noting its CVSS score and affected component, but offers no PoC, exploit code, or evidence of active exploitation.

    0000051
    172 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2025-41757 - MBS - UBR-01 Mk II - https://www.redpacketsecurity.com/cve-alert-cve-2025-41757-mbs-ubr-01-mk-ii/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-41757 #mbs #ubr-01-mk-ii

    Post summary

    The tweet announces CVE-2025-41757 in the MBS UBR-01 Mk II and links to an alert, but provides no further technical or exploitation information.

    00000153
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41757 A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the content… https://www.cve.org/CVERecord?id=CVE-2025-41757

    Post summary

    CVE‑2025‑41757 allows a low‑privileged attacker to misuse UBR’s backup restore feature, which runs with elevated privileges and lacks proper content validation.

    00000137
    56.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-41757 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-41757 #CVE-2025-41757 #CVE #High  #CyberSecurity #InfoSec https://t.co/jIraa7G5p2

    Post summary

    The tweet simply announces CVE-2025-41757 with a high severity score and provides a link to the NVD entry, offering no technical details, PoC, or exploitation information.

    0000071
    90 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-41757 Arbitrary File Write Vulnerability in UBR Restore Functionality with Elevated Privileges https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-41757

    Post summary

    The post simply announces CVE-2025-41757 as an arbitrary file write vulnerability in UBR Restore with elevated privileges, providing no details on PoC, exploitation, patching, or active attacks.

    0000046
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-41757 - High A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive t... https://www.thehackerwire.com/vulnerability/CVE-2025-41757/ https://t.co/IGUjjjBN1e

    Post summary

    The post announces the discovery of CVE-2025-41757, describing how an attacker can exploit the UBR backup restore function to run elevated code. No evidence of PoC, active exploitation, or patch is provided.

    0000063
    129 followersView on X
  • CVEFind.com@CveFindCom
    Active Exploitation

    [CVE-2025-41757: HIGH] Remote attackers exploiting UBR (ubr-restore) can create/overwrite files due to lacking backup archive validation, posing a serious cyber security threat.#cve,CVE-2025-41757,#cybersecurity https://cvefind.com/CVE-2025-41757

    Post summary

    CVE‑2025‑41757 enables attackers to create or overwrite files via the UBR restore function because of missing archive validation. The post highlights the active exploitation state and high severity but lacks PoC, patch, or tool details.

    0000054
    600 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWmbs-solutionsubr-01_mk_ii---
HWmbs-solutionsubr-02---
HWmbs-solutionsubr-lon---
OSmbs-solutionsuniversal_bacnet_router_firmware---

Explore more