


Perceptive Security
SOC/SIEM Consultancy

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This i…
Published:
8 March 2026 at 23:00:00
Alert date:
9 March 2026 at 10:01:37
Source:
nvd.nist.gov
Web Technologies, Critical Infrastructure
CVE-2025-41765 is a critical vulnerability affecting the wwwupload.cgi endpoint due to insufficient authorization enforcement. An unauthorized remote attacker can exploit this weakness to upload and apply arbitrary data including contact images, HTTPS certificates, system backups, server peer configurations, and BACnet/SC server certificates and keys. The vulnerability allows complete bypass of upload restrictions, potentially leading to system compromise through malicious file uploads. This affects various system components including certificate management and backup restoration functionality.
Technical details
Mitigation steps:
Affected products:
Related links:
Related CVE's:
Related threat actors:
IOC's:
wwwupload.cgi
This article was created with the assistance of AI technology by Perceptive.
