Impact
This vulnerability stems from a broken access control in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi. A remote user who has authenticated and holds even the low‑privileged Standard role can alter the passwords of any accounts on the system. This allows malicious actors to compromise the security of user accounts, potentially facilitating further unauthorized access or data exfiltration. The flaw represents a direct breach of account integrity and can undermine the overall trust model of the gateway.
Affected Systems
MBS‑Solutions X‑Serie Gateway firmware version V6_00_05. This firmware is used on a subset of MBS‑Solutions gateway devices, typically accessed via a web‑based interface.
Risk and Exploitability
The vulnerability is exploitable from any network location that can reach the gateway’s web interface, provided the attacker can log in as a Standard user. Once authenticated, the attacker can invoke the ugw‑usr‑edit method to reset or change passwords for arbitrary accounts. The EPSS is not available and the flaw is not listed in the CISA KEV catalog, but the lack of a defense such as proper authorization checks and the ease of triggering the method mean that exploitation is likely to occur in a real‑world environment. The CVSS score is not supplied, but the potential for widespread account compromise indicates a high severity risk.
OpenCVE Enrichment