Mbs-solutions Vulnerabilities

Comprehensive security vulnerability database for Mbs-solutions products

Last updated: Mar 9, 2026
Total CVEs

6

Critical

2

With Exploits

3

Last 30 Days

15

Severity Distribution

Critical2
33%
High7
117%
Medium6
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2025-417636.5

This vulnerability allows a low-privileged remote attacker to download sensitive files, such as system backups and certificate requests, from the device. The attacker can exploit this by accessing a specific web endpoint without needing high-level permissions.

mbs-solutionsuniversal bacnet router firmware
Exploit Available
30 days agoMar 9, 2026
CVE-2025-417626.2

An attacker can exploit a weakness in the backup process of the universal BACnet router firmware to access sensitive information, such as password hashes and certificates, without needing to log in. This vulnerability occurs because the backup files are protected by a weak hash, making it easier for unauthorized users to retrieve the data.

mbs-solutionsuniversal bacnet router firmware
Theoretical
30 days agoMar 9, 2026
CVE-2025-417604.9

This vulnerability allows an attacker to bypass security measures by sending any network traffic through the universal BACnet router, even if an administrator tries to block it with an empty filter list. The issue arises because the router does not enforce restrictions when the filter is empty, meaning no special conditions are needed for an attacker to exploit this flaw.

mbs-solutionsuniversal bacnet router firmware
Theoretical
30 days agoMar 9, 2026
CVE-2025-417594.9

This vulnerability allows an attacker to bypass network blocking controls by using unsupported identifiers like "*" or "all," which are incorrectly interpreted as allowing all networks instead of blocking them. For this to happen, an administrator must mistakenly configure the router with these values, thinking they are securing the network.

mbs-solutionsuniversal bacnet router firmware
Theoretical
30 days agoMar 9, 2026
CVE-2025-417556.5

An attacker can remotely read any file on the system by exploiting a flaw in the universal BACnet router firmware, as the software does not properly check the file names provided by the attacker. This requires the attacker to have low-level access, but they can manipulate a specific method to access sensitive information stored in files.

mbs-solutionsuniversal bacnet router firmware
Theoretical
30 days agoMar 9, 2026
CVE-2025-417546.5

This vulnerability allows a low-privileged remote attacker to read any file on the system by exploiting an unused API endpoint in the firmware of the universal BACnet router. The attacker only needs access to this specific method, which is not properly documented or secured.

mbs-solutionsuniversal bacnet router firmware
Theoretical
30 days agoMar 9, 2026

About Mbs-solutions Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Mbs-solutions products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.