CVE-2025-41772

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.

Scoring

Severity
HIGH
CVSS base score
7.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS probability
0.32%
CWE
CWE-598
Published
2026-03-09
Last modified
2026-03-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs