CVE-2025-41758Disclosure(mbs-solutions / ubr-01_mk_ii)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ubr-01_mk_ii
  • ubr-02
  • ubr-lon
  • universal_bacnet_router_firmware

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-09); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Products
ubr-01_mk_iiubr-02ubr-lonuniversal_bacnet_router_firmware

1 version affected across 4 products

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-09: 5Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Technical Details · 2026-03-09: 5Technical Details · 2026-03-12: 103-0903-1003-12
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-095
Disclosure5
2026-03-101
General1
2026-03-121
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-41758 (CVSS:8.8, HIGH) is Analyzed. A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to ..https://nvd.nist.gov/vuln/detail/CVE-2025-41758 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post provides disclosure details for CVE‑2025‑41758, noting a high‑severity arbitrary file write flaw in wwupload.cgi and linking to the NVD entry, but offers no PoC, exploitation code, or patch information.

    0000059
    172 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-41758 - MBS - UBR-01 Mk II - https://www.redpacketsecurity.com/cve-alert-cve-2025-41758-mbs-ubr-01-mk-ii/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-41758 #mbs #ubr-01-mk-ii

    Post summary

    The tweet links to a CVE alert for CVE-2025-41758 concerning the MBS UBR‑01 Mk II but provides no detail on the vulnerability type, PoC, exploit availability, active exploitation, or patch status.

    00000188
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41758 A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting ar… https://www.cve.org/CVERecord?id=CVE-2025-41758

    Post summary

    The post announces CVE-2025-41758, noting it allows low‑privileged remote attackers to perform arbitrary file writes through path traversal in the wwupload.cgi endpoint.

    00000138
    56.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-41758 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-41758 #CVE-2025-41758 #CVE #High  #CyberSecurity #InfoSec https://t.co/EHOa6HYqGf

    Post summary

    The tweet announces CVE-2025-41758 as a high‑risk vulnerability (CVSS 8.8) affecting multiple unspecified products and provides a link to the NVD entry.

    0000065
    90 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-41758 Arbitrary File Write Vulnerability in wwupload.cgi Endpoint via Path Traversal https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-41758

    Post summary

    The text identifies CVE-2025-41758 as an arbitrary file write vulnerability via path traversal in the wwupload.cgi endpoint, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000044
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-41758 - High A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the devi... https://www.thehackerwire.com/vulnerability/CVE-2025-41758/ https://t.co/lvO9Za7V7E

    Post summary

    The article announces CVE-2025-41758, detailing a low-privileged remote attacker able to perform arbitrary file writes via a path traversal flaw in wwupload.cgi, but does not provide POCs, exploit tools, active exploitation evidence, or patches.

    0000068
    129 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-41758: HIGH] Beware! A cyber attacker exploiting a file write vulnerability in wwupload.cgi endpoint can overwrite files on your system, leading to a full compromise. #cybersecurity#cve,CVE-2025-41758,#cybersecurity https://cvefind.com/CVE-2025-41758

    Post summary

    The post warns that CVE‑2025‑41758, a file‑write vulnerability in wwupload.cgi, could allow attackers to overwrite system files and gain full compromise, but it offers no PoC, exploit code, or patch information.

    0000061
    600 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWmbs-solutionsubr-01_mk_ii---
HWmbs-solutionsubr-02---
HWmbs-solutionsubr-lon---
OSmbs-solutionsuniversal_bacnet_router_firmware---

Explore more