Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Description
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
Problem types
CWE-1242 Inclusion of Undocumented Features or Chicken Bits
Product status
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
Credits
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
References
www.mbs-solutions.de/mbs-2025-0001