MBS Universal BACnet Router Arbitrary File Write Vulnerability in wwwubr.cgi

Vulnerability

A vulnerability exists in the MBS Universal BACnet Router's web interface, specifically within an undocumented API endpoint called wwwubr.cgi. The 'ubr-editfile' method allows low-privileged remote attackers to write arbitrary files to the system. This vulnerability is present in both the 32 MB and 64 MB RAM firmware versions. The issue arises because the 'ubr-editfile' method, likely a leftover from an older version, is unused and undocumented, yet it remains accessible for exploitation.

Impact

Exploitation of this vulnerability gives attackers full control over the file system. They can overwrite any file, replace existing scripts with malicious ones that will be executed, change passwords for web interface and SSH accounts, modify various configuration files, and manipulate network filters.

Remediation

Users are advised to update to the new firmware version V6.0.1.0 for the Universal BACnet Router. This update is available for both the 32 MB and 64 MB RAM versions. For more details, please check the release notes on the MBS Solutions website.

Added: Mar 9, 2026, 9:27 AM
Updated: Mar 9, 2026, 9:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.