A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a parameter specifying the log file to open (e.g., /tmp/weblog{some_number}), but this parameter is not properly validated, allowing an attacker to modify it to reference any file and retrieve its contents.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Mon, 09 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
Description A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a parameter specifying the log file to open (e.g., /tmp/weblog{some_number}), but this parameter is not properly validated, allowing an attacker to modify it to reference any file and retrieve its contents.
Title Arbitrary Read with ubr-logread
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-03-09T08:16:00.702Z

Reserved: 2025-04-16T11:18:45.759Z

Link: CVE-2025-41755

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-09T09:15:59.183

Modified: 2026-03-09T09:15:59.183

Link: CVE-2025-41755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses