CVE-2025-66269 - CVE House
Back to Database
Status published High CVE-2025-66269

Unquoted Service Path in UPSilon2000V6.0(RupsMon and USBMate) running as SYSTEM

Vulnerability Description

The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66269

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Abdul Mhanni

Affected Vendor

MegaTec Taiwan

View all reports →

Affected Software

UPSilon2000V6.0
Vulnerable Versions:
6.0.5

Timeline

Official Publish: November 26th, 2025
Last Modified: November 26th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)