An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Universal_bacnet_router_firmware | Mbs-solutions | * | 6.0.1.0 (excluding) |