Description
An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/.
Published: 2026-09-04
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the ugw-editfile method of /cgi-bin/wwwugw.cgi, enabling a remote authenticated user with the Standard role to write arbitrary content to files in /uxx/config/ and /ugw/config/. This allows manipulation of configuration files, potentially leading to unauthorized configuration changes or a full compromise if those files control critical gateway behavior. The weakness permits modification of system state, compromising confidentiality, integrity and possibly enabling escalation to higher privileges or remote code execution by altering executable or configuration files.

Affected Systems

Affected devices are MBS‑Solutions X‑Serie Gateway firmware V6_00_05. The audit mentions only the X‑Serie Gateway firmware version V6_00_05; no other vendors or product variants are listed.

Risk and Exploitability

The CVSS score is 6.3, indicating a medium severity, but the impact is high due to write access to key configuration directories. The exploit requires authentication with a Standard‑role account, a common role on the gateway. Because the vulnerability is remotely exploitable through a web interface, the risk is significant. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers with legitimate credentials can leverage this flaw to change gateway behavior.

Generated by OpenCVE AI on September 4, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the gateway firmware to a version that includes the fix for the ugw-editfile method.
  • Revoke Standard‑role write permissions where possible, limiting users to read‑only or minimal access.
  • Restrict management interface access to trusted networks or VPNs, and enforce strong authentication.
  • Monitor system logs for attempts to write to /uxx/config/ or /ugw/config/ and investigate any unauthorized changes.

Generated by OpenCVE AI on September 4, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Authenticated File Write in MBS‑Solutions X‑Serie Gateway Firmware V6_00_05

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T16:54:20.909Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75168

cve-icon Vulnrichment

Updated: 2026-09-04T16:53:48.449Z

cve-icon NVD

Status : Received

Published: 2026-09-04T16:17:58.813

Modified: 2026-09-04T17:16:57.610

Link: CVE-2026-75168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:45:04Z

Weaknesses