CVE-2025-41758
8.8MBS Solutions · MBS UBR Series (UBR-01 Mk II, UBR-02, UBR-LON)
A path traversal vulnerability in the wwupload.cgi endpoint allows a low-privileged remote attacker to overwrite arbitrary files, potentially resulting in full system compromise.
Executive summary
A path traversal vulnerability in MBS UBR series devices allows low-privileged attackers to achieve full system compromise through arbitrary file writes.
Vulnerability
The vulnerability exists in the wwupload.cgi endpoint, where improper validation of pathnames allows for path traversal. An attacker with low-level user privileges can exploit this to write files to arbitrary locations on the host device.
Business impact
The ability to overwrite arbitrary system files poses a severe risk to organizational infrastructure, as it enables an attacker to gain full control over the affected hardware. Given the CVSS score of 8.8, this vulnerability is classified as High severity, indicating a significant potential for unauthorized access, data integrity loss, and complete service disruption.
Remediation
Immediate Action: Update all affected MBS UBR devices to firmware version 6.0.1.0 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor system logs for unauthorized access attempts directed at the wwupload.cgi endpoint and investigate any unusual file modification events on the appliance.
Compensating Controls: Deploy a Web Application Firewall (WAF) or network-level access control list to restrict access to the wwupload.cgi endpoint to authorized administrative IP addresses only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the potential for full system compromise, this vulnerability requires immediate attention. Administrators must prioritize applying the firmware update to all vulnerable units to eliminate the underlying path traversal flaw. If patching is not immediately feasible, restrict network access to the management interface to reduce the attack surface.
Sources
Originally found and disclosed by Adrien Rey from Cyber Defense Campus Zurich, Daniel Hulliger from Armasuisse, per the CVE Program record.