« Volver al listado

CVE-2025-41766

Estado: AnalizadaAlta (8.8)—

A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-41766",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-41766",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-09T20:03:36.827793Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "MBS",
          "product": "UBR-01 Mk II",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "6.0.1.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "MBS",
          "product": "UBR-02",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "6.0.1.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "MBS",
          "product": "UBR-LON",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "6.0.1.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-09T09:16:01.173",
  "references": [
    {
      "url": "https://www.mbs-solutions.de/mbs-2025-0001",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "info@cert.vde.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise."
    },
    {
      "lang": "es",
      "value": "Un atacante remoto con pocos privilegios puede desencadenar un desbordamiento de búfer basado en pila mediante una solicitud HTTP POST manipulada utilizando el método ubr-network, lo que resulta en el compromiso total del dispositivo."
    }
  ],
  "lastModified": "2026-06-17T09:23:08.150",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4E2B246-5465-41DB-BD9A-1533A7508790",
              "versionEndExcluding": "6.0.1.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mbs-solutions:ubr-01_mk_ii:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0D812069-6738-4B82-992B-09BB239783AB"
            },
            {
              "criteria": "cpe:2.3:h:mbs-solutions:ubr-02:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B21413DE-E1FA-4B5C-A415-F8E70D7090BF"
            },
            {
              "criteria": "cpe:2.3:h:mbs-solutions:ubr-lon:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0C67EAC-C633-4037-B2C4-965455FFF2A0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}