Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-35084 A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-35085 A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-35082 The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied … Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-35083 A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.1 CVE-2026-35079 The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlle… Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.1 CVE-2026-35080 The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-contr… Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.1 CVE-2026-35081 The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied… Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 CRITICAL 9.8 CVE-2026-35075 An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. Universal Gateway Firmware 6_00_07+ Fix from $2,3002026-06-03 HIGH 8.1 CVE-2026-35076 The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-contro… Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.1 CVE-2026-35077 The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-cont… Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.1 CVE-2026-35078 The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controll… Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 HIGH 8.8 CVE-2025-41766 A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in … Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-41772 An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL parameters of the wwwupdate.c… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 HIGH 7.2 CVE-2025-41767 A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in … Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 CRITICAL 9.1 CVE-2025-41764 Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $2,3002026-03-09 CRITICAL 9.1 CVE-2025-41765 Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $2,3002026-03-09 HIGH 7.8 CVE-2025-41761 A low‑privileged local attacker who gains access to the UBR service account (e.g., via SSH) can escalate privileges to obtain full system access. Thi… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 MEDIUM 6.5 CVE-2025-41763 A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, includin… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,6002026-03-09 MEDIUM 6.2 CVE-2025-41762 An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauthorized access to sensitive da… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,6002026-03-09 HIGH 8.8 CVE-2025-41757 A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not val… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 HIGH 8.8 CVE-2025-41758 A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead … Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 HIGH 8.1 CVE-2025-41756 A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files … Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 MEDIUM 6.5 CVE-2025-41755 A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a param… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,6002026-03-09 MEDIUM 6.5 CVE-2025-41754 A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files o… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,6002026-03-09