top of page
perceptive_background_267k.jpg

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This i…

Published:

8 March 2026 at 23:00:00

Alert date:

9 March 2026 at 10:01:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Critical Infrastructure

CVE-2025-41765 is a critical vulnerability affecting the wwwupload.cgi endpoint due to insufficient authorization enforcement. An unauthorized remote attacker can exploit this weakness to upload and apply arbitrary data including contact images, HTTPS certificates, system backups, server peer configurations, and BACnet/SC server certificates and keys. The vulnerability allows complete bypass of upload restrictions, potentially leading to system compromise through malicious file uploads. This affects various system components including certificate management and backup restoration functionality.

Technical details

Mitigation steps:

Affected products:

Related links:

Related CVE's:

Related threat actors:

IOC's:

wwwupload.cgi

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page