Description
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Published: 2026-06-03
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ugw-restoreinfo method in MBS firmware allows a remote attacker who can obtain user privileges to delete any local file because user input is not validated against file-system boundaries. This weakness is classified as CWE‑73 and permits an attacker to remove critical configuration files or system data, potentially leading to loss of service or further damage if essential files are removed.

Affected Systems

All firmware versions of MBS products listed under the following categories are impacted: Double‑A Profibus, Double‑A x‑link, Double‑X CAN, Double‑X DALI, Double‑X KNX, Double‑X LON, Double‑X M‑Bus, Double‑X PROFINET, Double‑X x‑link, Single‑A, Single‑X, Triple‑X KNX+DALI, Triple‑X KNX+LON, Triple‑X KNX+M‑Bus, Triple‑X PROFINET+DALI, Triple‑X PROFINET+KNX, Triple‑X PROFINET+LON, and Triple‑X PROFINET+M‑Bus. Specific affected firmware versions are not disclosed, so any deployment of these products should be examined for the presence of the vulnerable method.

Risk and Exploitability

The CVSS score of 7.2 indicates a medium‑to‑high severity vulnerability with a potential for significant impact on integrity. EPSS data is unavailable, so the likelihood of exploitation cannot be precisely quantified, but the vulnerability is referenced in a VDE advisory, suggesting that knowledgeable actors could target it. The vulnerability is not currently listed in the CISA KEV catalog. As the attack vector is described as remote, an attacker must be able to invoke ugw-restoreinfo over the network or exploit a local user context; once the condition is met, the attacker can delete arbitrary files.

Generated by OpenCVE AI on June 3, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If a firmware update from MBS that addresses ugw-restoreinfo is available, install it immediately.
  • If no update exists, consider disabling or restricting the ugw-restoreinfo method in device configuration.
  • Limit user privileges so that normal operating users cannot invoke ugw-restoreinfo and monitor system logs for unauthorized deletion attempts.

Generated by OpenCVE AI on June 3, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Description The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Title Arbitrary file delete vulnerability in method ugw-restoreinfo
First Time appeared Mbs
Mbs double A Profibus Firmware
Mbs double A X Link Firmware
Mbs double X Can Firmware
Mbs double X Dali Firmware
Mbs double X Knx Firmware
Mbs double X Lon Firmware
Mbs double X M Bus Firmware
Mbs double X Profinet Firmware
Mbs double X X Link Firmware
Mbs single A Firmware
Mbs single X Firmware
Mbs triple X Knx Dali Firmware
Mbs triple X Knx Lon Firmware
Mbs triple X Knx M Bus Firmware
Mbs triple X Profinet Dali Firmware
Mbs triple X Profinet Knx Firmware
Mbs triple X Profinet Lon Firmware
Mbs triple X Profinet M Bus Firmware
Weaknesses CWE-73
CPEs cpe:2.3:o:mbs:double_a_profibus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_a_x_link_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_can_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_knx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_m_bus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_profinet_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:double_x_x_link_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:single_a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:single_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_knx_m_bus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_dali_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_knx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_lon_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbs:triple_x_profinet_m_bus_firmware:*:*:*:*:*:*:*:*
Vendors & Products Mbs
Mbs double A Profibus Firmware
Mbs double A X Link Firmware
Mbs double X Can Firmware
Mbs double X Dali Firmware
Mbs double X Knx Firmware
Mbs double X Lon Firmware
Mbs double X M Bus Firmware
Mbs double X Profinet Firmware
Mbs double X X Link Firmware
Mbs single A Firmware
Mbs single X Firmware
Mbs triple X Knx Dali Firmware
Mbs triple X Knx Lon Firmware
Mbs triple X Knx M Bus Firmware
Mbs triple X Profinet Dali Firmware
Mbs triple X Profinet Knx Firmware
Mbs triple X Profinet Lon Firmware
Mbs triple X Profinet M Bus Firmware
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mbs Double A Profibus Firmware Double A X Link Firmware Double X Can Firmware Double X Dali Firmware Double X Knx Firmware Double X Lon Firmware Double X M Bus Firmware Double X Profinet Firmware Double X X Link Firmware Single A Firmware Single X Firmware Triple X Knx Dali Firmware Triple X Knx Lon Firmware Triple X Knx M Bus Firmware Triple X Profinet Dali Firmware Triple X Profinet Knx Firmware Triple X Profinet Lon Firmware Triple X Profinet M Bus Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-06-03T12:34:20.844Z

Reserved: 2026-04-01T08:28:27.141Z

Link: CVE-2026-35080

cve-icon Vulnrichment

Updated: 2026-06-03T12:32:52.011Z

cve-icon NVD

Status : Received

Published: 2026-06-03T13:16:20.383

Modified: 2026-06-03T13:16:20.383

Link: CVE-2026-35080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T13:30:26Z

Weaknesses