Description
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Published: 2026-06-03
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug in the bac-scanresult method permits an attacker who can already gain user-level access on the device to erase any file on the local filesystem. This occurs because the input supplied to the method is not validated against path traversal or other sanitization checks. The result is the loss or corruption of configuration, data, or firmware files, potentially disabling the device or preventing recovery. The weakness is a classic Path Traversal defect (CWE‑73).

Affected Systems

Firmware for a wide range of MBS industrial automation gadgets is impacted. The affected products include MBS Double‑A Profibus, Double‑A x‑link, Double‑X CAN, Double‑X DALI, Double‑X KNX, Double‑X LON, Double‑X M‑Bus, Double‑X PROFINET, Double‑X x‑link, Single‑A, Single‑X, and various Triple‑X bundles that combine KNX, DALI, LON, and M‑Bus protocols. The advisory does not list specific firmware revisions, so any version that still uses the vulnerable bac‑scanresult routine is at risk until patched.

Risk and Exploitability

The calculated CVSS score of 7.2 indicates a moderately high impact with user privilege as a prerequisite. No EPSS value was supplied, so the real-world likelihood of exploitation cannot be quantified, and the vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the attacker must first achieve normal user credentials on the device, then invoke the vulnerable method—likely through a remote command or API call—to delete target files. The ability to destroy arbitrary local files can lead to a denial of service or a compromised configuration, and could serve as a foothold for further attacks once the device’s integrity is corrupted.

Generated by OpenCVE AI on June 3, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the vulnerable bac‑scanresult implementation
  • Constrain user accounts to the minimum set of permissions needed for operation, avoiding unnecessary local write access
  • Enforce file system access controls or quarantine measures to restrict deletable paths and log deletion attempts

Generated by OpenCVE AI on June 3, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Description The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Title Arbitrary file delete vulnerability in method bac-scanresult
First Time appeared Mbs
Mbs double A Profibus Firmware
Mbs double A X Link Firmware
Mbs double X Can Firmware
Mbs double X Dali Firmware
Mbs double X Knx Firmware
Mbs double X Lon Firmware
Mbs double X M Bus Firmware
Mbs double X Profinet Firmware
Mbs double X X Link Firmware
Mbs single A Firmware
Mbs single X Firmware
Mbs triple X Knx Dali Firmware
Mbs triple X Knx Lon Firmware
Mbs triple X Knx M Bus Firmware
Mbs triple X Profinet Dali Firmware
Mbs triple X Profinet Knx Firmware
Mbs triple X Profinet Lon Firmware
Mbs triple X Profinet M Bus Firmware
Weaknesses CWE-73
CPEs cpe:2.3:o:mbs:double_a_profibus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_a_x_link_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_can_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_knx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_m_bus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_profinet_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_x_link_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:single_a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:single_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_m_bus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_knx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_m_bus_firmware:*:*:*:*:*:*:*:*
Vendors & Products Mbs
Mbs double A Profibus Firmware
Mbs double A X Link Firmware
Mbs double X Can Firmware
Mbs double X Dali Firmware
Mbs double X Knx Firmware
Mbs double X Lon Firmware
Mbs double X M Bus Firmware
Mbs double X Profinet Firmware
Mbs double X X Link Firmware
Mbs single A Firmware
Mbs single X Firmware
Mbs triple X Knx Dali Firmware
Mbs triple X Knx Lon Firmware
Mbs triple X Knx M Bus Firmware
Mbs triple X Profinet Dali Firmware
Mbs triple X Profinet Knx Firmware
Mbs triple X Profinet Lon Firmware
Mbs triple X Profinet M Bus Firmware
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mbs Double A Profibus Firmware Double A X Link Firmware Double X Can Firmware Double X Dali Firmware Double X Knx Firmware Double X Lon Firmware Double X M Bus Firmware Double X Profinet Firmware Double X X Link Firmware Single A Firmware Single X Firmware Triple X Knx Dali Firmware Triple X Knx Lon Firmware Triple X Knx M Bus Firmware Triple X Profinet Dali Firmware Triple X Profinet Knx Firmware Triple X Profinet Lon Firmware Triple X Profinet M Bus Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-06-03T12:43:33.610Z

Reserved: 2026-04-01T08:28:27.141Z

Link: CVE-2026-35076

cve-icon Vulnrichment

Updated: 2026-06-03T12:43:30.403Z

cve-icon NVD

Status : Received

Published: 2026-06-03T13:16:19.560

Modified: 2026-06-03T13:16:19.560

Link: CVE-2026-35076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T13:30:26Z

Weaknesses