CVE 7.1 HIGH

Unquoted Service Path in UPSilon2000V6.0(RupsMon and USBMate) running as SYSTEM_CVE-2025-66269

7.1 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L

Description

The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in

Basic Information

ID CVE-2025-66269
Source Gridware
Published Nov 26, 2025 at 01:19
Modified Nov 26, 2025 at 01:26

Affected Product

Vendor MegaTec Taiwan
Product UPSilon2000V6.0
Version 6.0.5
Affected Versions MegaTec Taiwan UPSilon2000V6.0 6.0.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.