Description
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
Published: 2026-09-04
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in the X-Serie Gateway Firmware V6_00_05 allows an attacker who can reach the /cgi-bin/wwwugw.cgi or /cgi-bin/ugwdownload.cgi endpoints to elevate their privileges on the device. The flaw permits bypass of authentication or privilege checks, giving the attacker the ability to perform higher‑level operations that are normally restricted to administrative accounts. The severity of the impact is the potential for full control of the gateway if the escalation succeeds, affecting confidentiality, integrity, and availability of the network infrastructure.

Affected Systems

The vulnerability is reported for the X-Serie Gateway Firmware V6_00_05 from MBS Solutions. No precise vendor or product versions are listed beyond the firmware revision; therefore the affected systems are those running that specific firmware build.

Risk and Exploitability

The attack vector is remote; an attacker only needs network connectivity to the vulnerable CGI endpoints to exploit the flaw. No CVSS score or EPSS data is published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, making the current probability of exploitation unknown. Nonetheless, because the flaw leads directly to privilege escalation, the potential risk remains significant for any exposed device.

Generated by OpenCVE AI on September 4, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the X-Serie Gateway Firmware to the latest release provided by MBS Solutions
  • Configure firewall or router rules to allow access to /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi only from trusted internal networks
  • Restrict or disable the CGI endpoints if they are not required for normal operation
  • Review and audit device logs for signs of unauthorized access attempts to the affected endpoints

Generated by OpenCVE AI on September 4, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via X-Serie Gateway Firmware CGI Endpoints
Weaknesses CWE-269
CWE-284

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T19:26:43.944Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T16:17:57.827

Modified: 2026-09-04T20:17:26.533

Link: CVE-2026-75160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:30:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control