# CVE-2025-41754

## Summary

- **CVE ID:** CVE-2025-41754
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-1242
- **Published:** Mar 9, 2026
- **Last Modified:** Mar 9, 2026

## Description

A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system.

## Affected Products

- MBS — UBR-01 Mk II (0.0.0)
- MBS — UBR-02 (0.0.0)
- MBS — UBR-LON (0.0.0)

## References

- [CNA](https://www.mbs-solutions.de/mbs-2025-0001)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 26.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._