


Perceptive Security
SOC/SIEM Consultancy

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.
Published:
8 maart 2026 om 23:00:00
Alert date:
9 maart 2026 om 10:01:37
Source:
nvd.nist.gov
Web Technologies
CVE-2025-41764 is a high-severity vulnerability caused by insufficient authorization enforcement. An unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates to affected systems. This vulnerability allows complete bypass of authorization controls, potentially leading to system compromise. The flaw exists in the web interface's update mechanism, specifically targeting the wwwupdate.cgi script. Remote exploitation is possible without authentication, making this a critical security issue requiring immediate attention.
Technical details
Mitigation steps:
Affected products:
Related links:
Related CVE's:
Related threat actors:
IOC's:
wwwupdate.cgi
This article was created with the assistance of AI technology by Perceptive.
