CVE-2025-41772
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
HIGH · CVSS 7.5
EPSS 0.00057
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0