CVE-2025-41753

CRITICAL Status: Received

CVSS Scores

CVSS v3.x Base Score
9.8
CRITICAL

Description

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

Published
October 1, 2026 7:16 AM
Last Modified
October 1, 2026 7:16 AM
Source
[email protected]

Weaknesses (CWE)

CWE-22

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.