CVE-2025-41766Disclosure(mbs-solutions / ubr-01_mk_ii)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ubr-01_mk_ii
  • ubr-02
  • ubr-lon
  • universal_bacnet_router_firmware

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 6 mentions (2026-03-09); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Products
ubr-01_mk_iiubr-02ubr-lonuniversal_bacnet_router_firmware

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-03-09: 6Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Technical Details · 2026-03-09: 5Technical Details · 2026-03-12: 103-0903-1003-12
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-096
Disclosure6
2026-03-101
General1
2026-03-121
Disclosure1
Full discourse8 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-41766 (CVSS:8.8, HIGH) is Analyzed. A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr..https://nvd.nist.gov/vuln/detail/CVE-2025-41766 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A concise disclosure of CVE-2025-41766, describing a stack-based buffer overflow via crafted HTTP POST requests with a CVSS score of 8.8, indicating high severity.

    0000051
    172 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-41766 - MBS - UBR-01 Mk II - https://www.redpacketsecurity.com/cve-alert-cve-2025-41766-mbs-ubr-01-mk-ii/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-41766 #mbs #ubr-01-mk-ii

    Post summary

    The tweet merely announces or links to a CVE alert without offering concrete proof‑of‑concepts, exploit details, or remediation information.

    00000191
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41766 A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compr… https://www.cve.org/CVERecord?id=CVE-2025-41766

    Post summary

    The snippet outlines a stack‑based buffer overflow (CVE‑2025‑41766) exploitable by low‑privileged remote attackers via a crafted HTTP POST request over the ubr‑network method, potentially leading to full device compromise.

    00000122
    56.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-41766 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-41766 #CVE-2025-41766 #CVE #High  #CyberSecurity #InfoSec https://t.co/paWF7FGi92

    Post summary

    This tweet announces the new CVE-2025-41766 with a severity rating of 8.8, but offers no details beyond the NVD reference.

    0000049
    90 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-41766 Stack-Based Buffer Overflow in ubr-network Method Enables Remote Device Compromise https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-41766

    Post summary

    The text announces CVE-2025-41766 as a stack-based buffer overflow that can lead to remote device compromise, but it does not provide a PoC, exploit code, evidence of active exploitation, patches, or mitigations.

    0000055
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting MBS UBR-01 Mk II and other products (CVE-2025-41766) https://vuldb.com/?id.349810

    Post summary

    The post announces a newly reported CVE-2025-41766 vulnerability that affects MBS UBR-01 Mk II and other products, with a link to vuldb for more information.

    00000123
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-41766 - High A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise. https://www.thehackerwire.com/vulnerability/CVE-2025-41766/ https://t.co/7WMc8W6y4C

    Post summary

    CVE‑2025‑41766 is a stack‑based buffer overflow in firmware that can be triggered via a crafted HTTP POST request, potentially leading to full device compromise.

    0000078
    130 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-41766: HIGH] A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.#cve,CVE-2025-41766,#cybersecurity https://cvefind.com/CVE-2025-41766

    Post summary

    The tweet discloses a new high‑severity vulnerability (CVE-2025-41766) that allows a low‑privileged attacker to trigger a stack‑based buffer overflow via a crafted HTTP POST request, leading to full device compromise.

    0000072
    600 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWmbs-solutionsubr-01_mk_ii---
HWmbs-solutionsubr-02---
HWmbs-solutionsubr-lon---
OSmbs-solutionsuniversal_bacnet_router_firmware---

Explore more