CVE Vulnerabilities

CVE-2025-41760

Not Failing Securely ('Failing Open')

Published: Mar 09, 2026 | Modified: Mar 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an empty list does not enforce any restrictions and allows all network traffic to pass unfiltered.

Weakness

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Affected Software

NameVendorStart VersionEnd Version
Universal_bacnet_router_firmwareMbs-solutions*6.0.1.0 (excluding)

Potential Mitigations

References