CVE-2025-41762 PUBLISHED

Secret leak with wwwdnload.cgi

Assigner: CERTVDE
Reserved: 16.04.2025 Published: 09.03.2026 Updated: 09.03.2026

An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive data, including password hashes and certificates.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.2

Product Status

Vendor MBS
Product UBR-01 Mk II
Versions Default: unaffected
  • affected from 0.0.0 to 6.0.1.0 (excl.)
Vendor MBS
Product UBR-02
Versions Default: unaffected
  • affected from 0.0.0 to 6.0.1.0 (excl.)
Vendor MBS
Product UBR-LON
Versions Default: unaffected
  • affected from 0.0.0 to 6.0.1.0 (excl.)

Credits

  • Adrien Rey from Cyber Defense Campus Zurich finder
  • Daniel Hulliger from Armasuisse finder

References

Problem Types

  • CWE-328 Use of Weak Hash CWE