Impact
An authenticated information disclosure flaw exists in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi on MBS‑Solutions X‑Serie Gateways. This flaw allows any logged‑in user, including those with only the low‑privileged Standard role, to retrieve detailed firmware and operating system version data. The exposed information can assist attackers in determining the gateway’s software configuration, thereby aiding in the design of targeted exploits or other attack steps. The weakness is a classic Information Exposure vulnerability (CWE‑200).
Affected Systems
The described issue affects MBS‑Solutions X‑Serie Gateway firmware version V6_00_05. No other versions or products are listed as affected.
Risk and Exploitability
The vulnerability is reachable via the gateway’s web interface, so an attacker must first authenticate or otherwise gain access to the control panel. Once authenticated, the privileged role grants immediate access to the sensitive system fields. No EPSS data or KEV listing is available, and the CVSS score is 6.5; however, the ability to gather exact firmware versions is valuable and could hasten the exploitation of undisclosed bugs. Consequently, the risk is moderate for networks that expose the gateway to external or untrusted users, while the likelihood of exploitation remains unknown but potentially high given the ease of access once credentials are in hand.
OpenCVE Enrichment