7.1
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L
Description
The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in
Basic Information
ID
CVE-2025-66269
Source
Gridware
Published
Nov 26, 2025 at 01:19
Modified
Nov 26, 2025 at 01:26
Affected Product
Vendor
MegaTec Taiwan
Product
UPSilon2000V6.0
Version
6.0.5
Affected Versions
MegaTec Taiwan UPSilon2000V6.0 6.0.5