VYPR
Vendor

UBR

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2025-41772HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.

  • CVE-2025-41767HigMar 9, 2026
    risk 0.47cvss 7.2epss 0.00

    A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in the web interface of UBR.

  • CVE-2025-41760MedMar 9, 2026
    risk 0.32cvss 4.9epss 0.00

    An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an empty list does not enforce any restrictions and allows all network traffic to pass unfiltered.