CVE Vulnerabilities

CVE-2025-41759

Not Failing Securely ('Failing Open')

Published: Mar 09, 2026 | Modified: Mar 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An administrator may attempt to block all networks by specifying * or all as the network identifier. However, these values are not supported and do not trigger any validation error. Instead, they are silently interpreted as network 0 which results in no networks being blocked at all.

Weakness

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Affected Software

NameVendorStart VersionEnd Version
Universal_bacnet_router_firmwareMbs-solutions*6.0.1.0 (excluding)

Potential Mitigations

References