CVE Vulnerabilities

CVE-2025-41772

Use of GET Request Method With Sensitive Query Strings

Published: Mar 09, 2026 | Modified: Mar 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
Universal_bacnet_router_firmwareMbs-solutions*6.0.1.0 (excluding)

Potential Mitigations

References