OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2025-41753

CRITICAL · CVSS 9.8 EPSS 0.59%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A vulnerability exists in the handling of dynamically created BACnet File Objects, allowing an unauthenticated remote attacker to exploit insufficient validation of file paths. This can lead to directory traversal, enabling the attacker to read or overwrite arbitrary files on the device, potentially resulting in full system compromise. Organizations utilizing BACnet-enabled devices should prioritize patching this critical vulnerability to mitigate the risk of unauthorized access and data manipulation.

CVE
CVE-2025-41753
Severity
CRITICAL
CVSS
9.8
EPSS
0.59%

Original NVD Description

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.