← back
CVE-2025-41765

Unchecked role in wwwupload.cgi

CVSS 9.1 CRITICALEPSS 0.3%CWE-862
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/SC server certificates and keys.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →