High severity7.8NVD Advisory· Published Mar 9, 2026· Updated Jun 17, 2026
CVE-2025-41761
CVE-2025-41761
Description
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:mbs-solutions:universal_bacnet_router_firmware:*:*:*:*:*:*:*:*Range: <6.0.1.0
- MBS/UBR-01 Mk IIv5Range: 0.0.0
- MBS/UBR-02v5Range: 0.0.0
- MBS/UBR-LONv5Range: 0.0.0
Patches
Vulnerability mechanics
References
1- www.mbs-solutions.de/mbs-2025-0001nvdVendor Advisory
News mentions
0No linked articles in our index yet.