<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cimetrics - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/cimetrics/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:39:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/cimetrics/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Cimetrics BACstac</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2025-41753/</link><pubDate>Thu, 01 Oct 2026 10:39:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2025-41753/</guid><description>An unauthenticated remote attacker can exploit a path traversal vulnerability in Cimetrics BACstac to read or overwrite arbitrary files via maliciously crafted BACnet File Object names.</description><content:encoded><![CDATA[<p>CVE-2025-41753 describes a critical path traversal vulnerability within the Cimetrics BACstac software. The vulnerability exists because the application interprets the object name of a dynamically created BACnet File Object as a file path without performing sufficient input validation. Because the system fails to restrict paths to the intended directory, an unauthenticated, remote attacker can supply a crafted, relative path as the object name. This behavior allows the attacker to traverse outside the designated file directory to read or overwrite arbitrary files on the underlying host system. Successful exploitation poses a risk of full system compromise, as an attacker could potentially overwrite configuration files or inject malicious binaries to achieve remote code execution. Given the critical CVSS 9.8 score and the nature of industrial control system (ICS) protocols, this vulnerability represents a significant risk to the integrity and availability of affected industrial environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to gain unauthorized read/write access to the file system. This can lead to the exfiltration of sensitive configuration data, the disruption of critical industrial processes through file modification, or full system takeover via remote code execution. Impact is concentrated in industrial sectors utilizing the BACstac software stack for building automation and control.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of Cimetrics BACstac within the environment and evaluate exposure to the network.</li>
<li>Implement strict network segmentation and firewall rules to limit access to BACnet services (UDP 47808) to trusted, authorized systems only.</li>
<li>Prioritize the application of patches or vendor-provided updates to address CVE-2025-41753 immediately upon release.</li>
<li>Monitor logs for unusual file system access attempts or unexpected modifications to configuration files on hosts running BACstac.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>ics</category><category>scada</category><category>vulnerability</category><category>path-traversal</category></item></channel></rss>