Impact
An issue in the X-Serie Gateway Firmware V6_00_05 allows an attacker who can reach the /cgi-bin/wwwugw.cgi or /cgi-bin/ugwdownload.cgi endpoints to elevate their privileges on the device. The flaw permits bypass of authentication or privilege checks, giving the attacker the ability to perform higher‑level operations that are normally restricted to administrative accounts. The severity of the impact is the potential for full control of the gateway if the escalation succeeds, affecting confidentiality, integrity, and availability of the network infrastructure.
Affected Systems
The vulnerability is reported for the X-Serie Gateway Firmware V6_00_05 from MBS Solutions. No precise vendor or product versions are listed beyond the firmware revision; therefore the affected systems are those running that specific firmware build.
Risk and Exploitability
The attack vector is remote; an attacker only needs network connectivity to the vulnerable CGI endpoints to exploit the flaw. No CVSS score or EPSS data is published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, making the current probability of exploitation unknown. Nonetheless, because the flaw leads directly to privilege escalation, the potential risk remains significant for any exposed device.
OpenCVE Enrichment