Impact
The firmware contains an insecure permission setting that allows the low‑privileged service user to execute the system utility /usr/bin/tcpdump as root without any authentication. By invoking tcpdump with the -z option, an authenticated attacker can cause the utility to run arbitrary commands as root. This flaw is a classic example of privilege escalation, corresponding to CWE‑269.
Affected Systems
The vulnerability applies to MBS‑Solutions X‑Serie Gateway firmware version 6.00.05. Devices running this exact release are affected.
Risk and Exploitability
Based on the description, it is inferred that an attacker who can authenticate to the device can execute any command as root by using the tcpdump -z option. The exploit requires only local authenticated access to the gateway and does not depend on additional network exposure. The EPSS score of < 1% indicates that the likelihood of recent exploitation is very low; however the vulnerability is not listed in the CISA KEV catalog. The ability to run arbitrary code as root means that a successful exploit could compromise the gateway and potentially pivot to other network assets.
OpenCVE Enrichment