CVE Database
/

CVE-2025-66269

Back to search

CVE-2025-66269

Published: Nov 26, 2025

Modified: Nov 26, 2025

PUBLISHED

Description

The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in

VendorProductVersions

MegaTec Taiwan

UPSilon2000V6.0

affected
6.0.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now