Impact
The ugw‑restart method in the /cgi‑bin/wwwugw.cgi script of MBS‑Solutions X‑Serie Gateway firmware V6_00_05 contains a command injection flaw. An attacker who is authenticated but has only the low‑privileged Standard role can supply arbitrary input that is executed by the dpcheck system utility as root. This enables remote code execution, allowing full compromise of the gateway, data exfiltration, or further lateral movement.
Affected Systems
The vulnerability affects MBS‑Solutions X‑Serie Gateway firmware V6_00_05. Users running this firmware should verify their deployed devices and firmware version.
Risk and Exploitability
Because the flaw requires authentication as a Standard role, the attacker must first gain valid credentials. However, once authenticated, the attacker can execute code with root privileges, a high‑impact outcome. No EPSS score is available, and the issue is not listed in CISA KEV, so the precise exploitation likelihood is unknown. The CVSS score is not provided here, but the potential for full system compromise warrants immediate action.
OpenCVE Enrichment