MBS Universal BACnet Router UBR Web Interface Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability exists in the MBS Universal BACnet Router UBR web interface, specifically within the wwwupload.cgi endpoint. Due to inadequate authorization checks, an unauthorized remote attacker can upload and overwrite arbitrary files, including contact images, HTTPS certificates, system backups, server peer configurations, and BACnet/SC server certificates and keys. This vulnerability affects both the 32 MB and 64 MB RAM versions of the UBR firmware.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which can be used to overwrite existing files or introduce malicious scripts that could be executed on the device. Additionally, it could lead to unauthorized access by uploading files that contain sensitive information or credentials.

Reproduction

To reproduce this vulnerability, send a POST request to the wwwupload.cgi endpoint with a file parameter that is not one of the two expected contact image names. The file will be uploaded to a location that allows overwriting of sensitive files on the device.

Remediation

Users are advised to update to the latest UBR firmware version 6.0.1.0, which addresses this vulnerability.

Added: Mar 9, 2026, 9:23 AM
Updated: Mar 9, 2026, 9:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.6
remediation
0.0
relevance
3.9
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.