← back
CVE-2025-41764criticalCWE-862

Unchecked role in wwwupdate.cgi

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.1epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
In short

A vulnerability in the wwwupdate.cgi file allows anyone on the internet to upload and install malicious software updates without proper permission checks. This is critical because attackers can completely take over the affected system.

Technical detail

CWE-862 (Missing Authorization) allows unauthenticated remote attackers to access the wwwupdate.cgi endpoint and upload arbitrary update packages due to insufficient authorization controls. The vulnerability enables unauthorized code execution with system privileges, resulting in complete system compromise.

Summary generated and translated by AI from the official description.
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H