CVE-2025-41757

8.8

MBS Solutions · UBR (UBR-01 Mk II, UBR-02, UBR-LON)

A path traversal vulnerability in the UBR backup restore functionality allows low-privileged remote attackers to create or overwrite arbitrary files on the system via malicious backup archives.

Executive summary

A critical path traversal vulnerability in MBS UBR backup solutions permits low-privileged remote attackers to achieve arbitrary file write access, potentially leading to full system compromise.

Vulnerability

This is a path traversal flaw (CWE-22) residing in the ubr-restore utility. The utility fails to validate the contents of backup archives, allowing an authenticated low-privileged attacker to perform unauthorized file operations with elevated system privileges.

Business impact

Successful exploitation allows an attacker to overwrite sensitive system files, which can result in remote code execution, unauthorized configuration changes, or complete system takeover. Given the CVSS score of 8.8, this vulnerability represents a high risk to data integrity and system availability, as it bypasses standard access controls to manipulate critical OS components.

Remediation

Immediate Action: Update all affected MBS UBR units to version 6.0.1.0 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for unauthorized access to the ubr-restore utility and inspect backup archives for suspicious directory traversal sequences.

Compensating Controls: Restrict network access to the management interfaces of UBR devices to trusted administrators only, and ensure that backup archives originate from verified and secure sources.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

This vulnerability poses a severe risk to organizational infrastructure due to the potential for arbitrary file manipulation. IT administrators should prioritize the deployment of the 6.0.1.0 update across all affected MBS UBR hardware immediately to prevent potential exploitation.

Sources

Originally found and disclosed by Adrien Rey from Cyber Defense Campus Zurich, Daniel Hulliger from Armasuisse, per the CVE Program record.