Description

A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. This is due to the service account being permitted to execute certain binaries (e.g., tcpdump and ip) with sudo.

INFO

Published Date :

2026-03-09T08:17:11.116Z

Last Modified :

2026-03-09T20:14:04.600Z

Source :

CERTVDE
AFFECTED PRODUCTS

The following products are affected by CVE-2025-41761 vulnerability.

Vendors Products
Mbs
  • Ubr-01 Mk Ii
  • Ubr-02
  • Ubr-lon
Mbs-solutions
  • Ubr-01 Mk Ii
  • Ubr-02
  • Ubr-lon
  • Universal Bacnet Router Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-41761.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact