MBS Universal BACnet Router Arbitrary File Write Vulnerability in wwupload.cgi Endpoint

Vulnerability

An arbitrary file write vulnerability has been identified in the MBS Universal BACnet Router's web interface, specifically within the wwupload.cgi endpoint. This vulnerability arises from a path traversal issue, allowing low-privileged remote attackers to overwrite arbitrary files on the device, potentially leading to a full system compromise. The vulnerability affects both the 32 MB and 64 MB RAM firmware versions.

Impact

Exploitation of this vulnerability allows an attacker to gain full control over the file system. They can overwrite any file, replace existing scripts with malicious ones that will be executed, change passwords for web interface and SSH accounts, modify various configuration files, and manipulate network filters.

Reproduction

To reproduce this vulnerability, upload a file through the wwupload.cgi endpoint by manually changing the file parameter to a name other than the default contact1.png or contact2.png. The file will be uploaded to the /ubr/config directory, overwriting any existing files. This can be done by sending a crafted HTTP POST request with the modified file name.

Remediation

MBS GmbH has released a firmware update to version V6.0.1.0 for the Universal BACnet Router. Users are advised to install this update immediately.

Added: Mar 9, 2026, 9:26 AM
Updated: Mar 9, 2026, 9:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.6
remediation
0.0
relevance
3.8
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.