VYPR

BACnet File Object

by Bacnetstack

CVEs (1)

  • CVE-2025-41753CriOct 1, 2026
    risk 0.64cvss 9.8epss —

    The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite…