Back to Database
Status published
Critical
CVE-2025-41764
Unchecked role in wwwupdate.cgi
Vulnerability Description
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41764
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Adrien Rey from Cyber Defense Campus Zurich
- Daniel Hulliger from Armasuisse
References
More from MBS
View All →CVE-2025-41772
wwwupdate.cgi Session token in URL
High
7.5
CVE-2025-41767
Signature bypass on update upload
High
7.2
CVE-2025-41766
Stack buffer overflow on parsing web request
High
8.8
CVE-2025-41765
Unchecked role in wwwupload.cgi
Critical
9.1
CVE-2025-41763
Unchecked role in wwwdnload.cgi
Medium
6.5
Affected Vendor
Affected Software
UBR-01 Mk II, UBR-02, UBR-LON
Vulnerable Versions:
0.0.0
Timeline
Official Publish:
March 9th, 2026
Last Modified:
March 9th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H