CVE-2025-66269: Megatec Taiwan UPSILON2000V6.0
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This allows a local attacker to perform path interception and escalate privileges if they have write permissions to the directories proceeding that of which the real service executables live in
Affected products
- Megatec Taiwan UPSILON2000V6.0: version 6.0.5 only
Published 2025-11-26. Last modified 2026-06-17.