External risk intelligence

BACnet File Object Path Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-41753

This vulnerability affects BACnet, a protocol used primarily in building automation and control systems. While network-reachable in some industrial or building environments, these devices are typically deployed within private, isolated operational technology networks and are not intended to be directly exposed to the public internet.

Path Traversal

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in certain building automation systems. This issue allows an unauthenticated remote attacker to read or overwrite arbitrary files on the device, potentially leading to a full system compromise. The main concern is confirming relevance and exposure within your operational technology environments.

  • Attackers can read/overwrite sensitive files.
  • Unauthenticated remote access is possible.
  • Confirm relevance and exposure in OT environments.

Attack Path

How an attacker could exploit the issue

An unauthenticated remote attacker can exploit this vulnerability by leveraging the improper interpretation of dynamically created BACnet File Object names. These names are treated as file paths without sufficient validation, allowing the attacker to navigate outside the intended directory. This enables them to read or overwrite arbitrary files on the device, potentially leading to complete system compromise.

  • No authentication required for access.
  • Attacker controls file path naming.
  • Risk of arbitrary file read/write.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to read or overwrite arbitrary files on the device by manipulating the object name of a dynamically created BACnet File Object. This could lead to a full system compromise when the device's BACnet service is accessible over the network and file path validation is insufficient.

  • Arbitrary files on the device.
  • Path traversal, when supported by the advisory.
  • Full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in dynamically created BACnet File Objects could allow an unauthenticated remote attacker to read or overwrite arbitrary files, potentially leading to full system compromise. Real-world remediation will likely involve application owners, infrastructure teams, and security teams. The first practical step is to identify all instances of the affected technology, confirm their network reachability and business criticality, and then assign ownership for risk-based remediation planning.

  • Assign ownership to the affected technology.
  • Verify network exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is BACnet in the context of CVE-2025-41753?

BACnet is a standardized communication protocol widely used in building automation and control systems. It enables devices like HVAC controllers, lighting systems, and security monitors to exchange data and manage building infrastructure. This vulnerability specifically impacts the BACnet File Object, a feature designed for file storage or transfer within these automated environments.

What does path traversal mean for this vulnerability?

This is a CWE-22 weakness, known as Improper Limitation of a Pathname to a Restricted Directory. In this case, the system fails to properly validate the names of dynamically created BACnet File Objects. An attacker can inject special characters, like navigation sequences, into the object name to escape the designated storage directory and access or modify files elsewhere on the device's system.

How does an attacker trigger this file access?

An attacker triggers this by interacting with the BACnet service over the network to create or name a File Object. Because the device does not validate the path, the attacker can use relative path sequences to traverse the file system. Note that the vulnerability is tied to the file naming process; simply viewing legitimate, properly configured files that do not involve path manipulation does not trigger the flaw.

Why should I care about this if my devices are internal?

According to Halo Surface Signal, this vulnerability is classified as unlikely to be directly internet-facing because BACnet is typically deployed in isolated operational technology networks. However, you should still care if your internal network allows broad access between corporate and OT segments, as an attacker already inside your perimeter could reach these devices and exploit the file system.

What are the first steps to address this issue?

Begin by inventorying your environment to locate all systems running BACnet services. Once identified, evaluate the network reachability of these devices and assess their business criticality. Coordinate with your infrastructure and security teams to determine which assets are reachable from untrusted segments and prioritize those for risk-based remediation planning.

References