CVE-2025-66266: Megatec Taiwan UPSILON2000V6.0
Critical severity, CVSS 9.3. EPSS: 0.1% chance of exploitation in the next 30 days.
The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply change the config path of the service to a command; starting and stopping the service to immediately achieve code execution and privilege escalation
Affected products
- Megatec Taiwan UPSILON2000V6.0: version 6.0.5 only
Published 2025-11-26. Last modified 2026-06-17.