Impact
An arbitrary file read vulnerability exists in the /cgi-bin/ugwdownload.cgi script of the MBS‑Solutions X‑Serie Gateway firmware. A remote authenticated user with the low‑privileged Standard role can craft a file query string to retrieve any file from the device filesystem. This allows an attacker to read configuration data, credentials, logs, or other sensitive files, thereby exposing confidential information. The flaw does not directly modify data or enable remote code execution, but the information disclosure could support further attacks such as privilege escalation or network reconnaissance.
Affected Systems
MBS‑Solutions X‑Serie Gateway firmware version V6_00_05 is affected. The vulnerability is present in the public firmware build for this gateway model and affects any device running that specific firmware release.
Risk and Exploitability
The attack vector requires remote authenticated access with a Standard role account, implying the attacker must either compromise valid credentials or exploit an existing authenticated session. The CVSS score of 6.5 is available, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, limiting public exploit awareness. Nonetheless, the ability to read arbitrary files is a significant confidentiality risk and represents a high impact if standard accounts can be accessed. Until a patch is applied or mitigated, the gateway remains vulnerable to data theft by any actor possessing Standard‑role credentials, potentially enabling further malicious activity.
OpenCVE Enrichment