CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.
CVE
CVE-2025-41772
Severity
HIGH
CVSS
7.5
EPSS
0.32%
Original NVD Description
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.cgi endpoint in UBR.
Related CVEs
Other vulnerabilities affecting the same vendor(s)