Description
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Read
Action: Immediate patch
AI Analysis

Impact

An arbitrary file read vulnerability exists in the /cgi-bin/ugwdownload.cgi script of the MBS‑Solutions X‑Serie Gateway firmware. A remote authenticated user with the low‑privileged Standard role can craft a file query string to retrieve any file from the device filesystem. This allows an attacker to read configuration data, credentials, logs, or other sensitive files, thereby exposing confidential information. The flaw does not directly modify data or enable remote code execution, but the information disclosure could support further attacks such as privilege escalation or network reconnaissance.

Affected Systems

MBS‑Solutions X‑Serie Gateway firmware version V6_00_05 is affected. The vulnerability is present in the public firmware build for this gateway model and affects any device running that specific firmware release.

Risk and Exploitability

The attack vector requires remote authenticated access with a Standard role account, implying the attacker must either compromise valid credentials or exploit an existing authenticated session. The CVSS score of 6.5 is available, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, limiting public exploit awareness. Nonetheless, the ability to read arbitrary files is a significant confidentiality risk and represents a high impact if standard accounts can be accessed. Until a patch is applied or mitigated, the gateway remains vulnerable to data theft by any actor possessing Standard‑role credentials, potentially enabling further malicious activity.

Generated by OpenCVE AI on September 4, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release that contains the fix for the arbitrary file read vulnerability
  • Restrict or temporarily disable Standard role access on affected devices to prevent the use of the vulnerable endpoint
  • Implement network segmentation and continuous monitoring of firmware management traffic to detect and block unauthorized file retrieval attempts

Generated by OpenCVE AI on September 4, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Mbs-solutions
Mbs-solutions x-serie Gateway
Vendors & Products Mbs-solutions
Mbs-solutions x-serie Gateway

Sat, 05 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-552
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.
References

Subscriptions

Mbs-solutions X-serie Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T19:25:25.401Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75164

cve-icon Vulnrichment

Updated: 2026-09-04T19:25:16.614Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T16:17:58.330

Modified: 2026-09-08T19:42:20.313

Link: CVE-2026-75164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:26:59Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties