# CVE-2025-41772

## Summary

- **CVE ID:** CVE-2025-41772
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-598
- **Published:** Mar 9, 2026
- **Last Modified:** Mar 9, 2026

## Description

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.

## Affected Products

- MBS — UBR-01 Mk II (0.0.0)
- MBS — UBR-02 (0.0.0)
- MBS — UBR-LON (0.0.0)

## References

- [CNA](https://www.mbs-solutions.de/mbs-2025-0001)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._