Impact
An issue in the X-Serie Gateway Firmware V6_00_05 allows an attacker who can reach the /cgi-bin/wwwugw.cgi or /cgi-bin/ugwdownload.cgi endpoints to bypass authentication or privilege checks and elevate their privileges on the device. This flaw can give the attacker the ability to execute commands or perform actions normally reserved for administrative users, potentially leading to full control of the gateway and compromising network confidentiality, integrity, and availability. The vulnerability is classified as a high‑severity privilege escalation that, if exploited, would allow an adversary to alter device configuration, intercept traffic, or disable services.
Affected Systems
The vulnerability is limited to the X-Serie Gateway firmware version V6_00_05, which is distributed by the device manufacturer. Any unit operating that specific firmware build is susceptible; newer firmware releases may not contain the same flaw, but devices not updated remain at risk.
Risk and Exploitability
The attack vector is remote; an attacker only needs network connectivity to the vulnerable CGI endpoints to exploit the flaw. The CVSS score of 9.1 reflects a high risk of successful privilege escalation with low complexity. EPSS score is unavailable, and the issue is not listed in the CISA KEV catalogue, so the exact probability of exploitation is unknown. Nonetheless, because the flaw permits complete bypass of access controls, the potential impact remains significant for any exposed device.
OpenCVE Enrichment