{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bacstac/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cimetrics:bacstac:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-41753"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BACstac"],"_cs_severities":["critical"],"_cs_tags":["ics","scada","vulnerability","path-traversal"],"_cs_type":"advisory","_cs_vendors":["Cimetrics"],"content_html":"\u003cp\u003eCVE-2025-41753 describes a critical path traversal vulnerability within the Cimetrics BACstac software. The vulnerability exists because the application interprets the object name of a dynamically created BACnet File Object as a file path without performing sufficient input validation. Because the system fails to restrict paths to the intended directory, an unauthenticated, remote attacker can supply a crafted, relative path as the object name. This behavior allows the attacker to traverse outside the designated file directory to read or overwrite arbitrary files on the underlying host system. Successful exploitation poses a risk of full system compromise, as an attacker could potentially overwrite configuration files or inject malicious binaries to achieve remote code execution. Given the critical CVSS 9.8 score and the nature of industrial control system (ICS) protocols, this vulnerability represents a significant risk to the integrity and availability of affected industrial environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized read/write access to the file system. This can lead to the exfiltration of sensitive configuration data, the disruption of critical industrial processes through file modification, or full system takeover via remote code execution. Impact is concentrated in industrial sectors utilizing the BACstac software stack for building automation and control.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of Cimetrics BACstac within the environment and evaluate exposure to the network.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and firewall rules to limit access to BACnet services (UDP 47808) to trusted, authorized systems only.\u003c/li\u003e\n\u003cli\u003ePrioritize the application of patches or vendor-provided updates to address CVE-2025-41753 immediately upon release.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual file system access attempts or unexpected modifications to configuration files on hosts running BACstac.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T10:39:41Z","date_published":"2026-10-01T10:39:41Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2025-41753/","summary":"An unauthenticated remote attacker can exploit a path traversal vulnerability in Cimetrics BACstac to read or overwrite arbitrary files via maliciously crafted BACnet File Object names.","title":"Path Traversal Vulnerability in Cimetrics BACstac","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2025-41753/"}],"language":"en","title":"CraftedSignal Threat Feed - BACstac","version":"https://jsonfeed.org/version/1.1"}