Vulnerabilities (CVE)

Total 398612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-41772 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 7.5 HIGH
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
CVE-2025-41768 2026-06-17 N/A 5.5 MEDIUM
An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to improper neutralization of input during web page generation ('Cross-site Scripting').
CVE-2025-41767 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 7.2 HIGH
A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in the web interface of UBR.
CVE-2025-41766 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 8.8 HIGH
A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full device compromise.
CVE-2025-41765 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 9.1 CRITICAL
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server certificates and keys.
CVE-2025-41764 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 9.1 CRITICAL
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.
CVE-2025-41763 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 6.5 MEDIUM
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, including system backups and certificate request files.
CVE-2025-41762 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 6.2 MEDIUM
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.
CVE-2025-41761 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 7.8 HIGH
A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.
CVE-2025-41760 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 4.9 MEDIUM
An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an empty list does not enforce any restrictions and allows all network traffic to pass unfiltered.
CVE-2025-41759 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 4.9 MEDIUM
An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these values are not supported and do not trigger any validation error. Instead, they are silently interpreted as network 0 which results in no networks being blocked at all.
CVE-2025-41758 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 8.8 HIGH
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.
CVE-2025-41757 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 8.8 HIGH
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.
CVE-2025-41756 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 8.1 HIGH
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
CVE-2025-41755 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 6.5 MEDIUM
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a parameter specifying the log file to open (e.g., /tmp/weblog{some_number}), but this parameter is not properly validated, allowing an attacker to modify it to reference any file and retrieve its contents.
CVE-2025-41754 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 6.5 MEDIUM
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system.
CVE-2025-41752 1 Phoenixcontact 137 Fl Nat 2008, Fl Nat 2008 Firmware, Fl Nat 2208 and 134 more 2026-06-17 N/A 7.1 HIGH
An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
CVE-2025-41751 1 Phoenixcontact 137 Fl Nat 2008, Fl Nat 2008 Firmware, Fl Nat 2208 and 134 more 2026-06-17 N/A 7.1 HIGH
An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
CVE-2025-41750 1 Phoenixcontact 137 Fl Nat 2008, Fl Nat 2008 Firmware, Fl Nat 2208 and 134 more 2026-06-17 N/A 7.1 HIGH
An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.
CVE-2025-41749 1 Phoenixcontact 137 Fl Nat 2008, Fl Nat 2008 Firmware, Fl Nat 2208 and 134 more 2026-06-17 N/A 7.1 HIGH
An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as operating system internals or privileged functions. Access is limited to device configuration parameters that are available in the context of the web application. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.