Description
An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The issue is located in the /cgi-bin/wwwugw.cgi script of MBS‑Solutions X‑Serie Gateway firmware V6_00_05. It allows a remote authenticated user with the low‑privileged Standard role to invoke hidden network diagnostic methods – ugw‑ping and ugw‑traceroute – that are not exposed in the web UI. Because these commands expose IP addresses, routing tables, and other network topology information, an attacker can obtain sensitive data that may aid further attacks. The vulnerability exemplifies improper access control and information disclosure, matching CWE‑285.

Affected Systems

The affected systems are MBS‑Solutions X‑Serie Gateway routers running firmware version V6_00_05. The vulnerability is present in the web CGI interface of this firmware.

Risk and Exploitability

The attack vector requires remote authentication; a user must already possess valid credentials for the gateway and be assigned the Standard role. Once authenticated, the attacker can trigger the hidden diagnostic calls manually or via automated scripts. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so current exploitation likelihood is low. The CVSS score is 6.5, indicating a moderate impact that includes leakage of network configuration details, which could aid subsequent reconnaissance or network compromise if privileges are later escalated.

Generated by OpenCVE AI on September 10, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MBS‑Solutions X‑Serie Gateway firmware to a patched version once released by the vendor.
  • Configure the gateway to restrict the Standard role from invoking network diagnostic functions, or disable the ugw‑ping and ugw‑traceroute capabilities via configuration settings.
  • Block remote access to /cgi-bin/wwwugw.cgi from untrusted networks using firewall rules or network segmentation.
  • Monitor gateway logs for unexpected usage of hidden diagnostic methods and review user role assignments regularly.

Generated by OpenCVE AI on September 10, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Access to Hidden Network Diagnostic Methods on MBS‑Solutions Gateway

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Network Diagnostic Disclosure in MBS‑Solutions X‑Serie Gateway
Weaknesses CWE-200
CWE-284

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Mbs-solutions
Mbs-solutions x-serie Gateway
Vendors & Products Mbs-solutions
Mbs-solutions x-serie Gateway

Fri, 04 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Network Diagnostic Disclosure in MBS‑Solutions X‑Serie Gateway
Weaknesses CWE-200
CWE-284

Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.
References

Subscriptions

Mbs-solutions X-serie Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-08T14:07:43.354Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75165

cve-icon Vulnrichment

Updated: 2026-09-08T14:07:32.342Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T16:17:58.450

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-75165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:15:14Z

Weaknesses