Impact
The vulnerability is located in the ugw-editfile method of /cgi-bin/wwwugw.cgi, enabling a remote authenticated user with the Standard role to write arbitrary content to files in /uxx/config/ and /ugw/config/. This allows manipulation of configuration files, potentially leading to unauthorized configuration changes or a full compromise if those files control critical gateway behavior. The weakness permits modification of system state, compromising confidentiality, integrity and possibly enabling escalation to higher privileges or remote code execution by altering executable or configuration files.
Affected Systems
Affected devices are MBS‑Solutions X‑Serie Gateway firmware V6_00_05. The audit mentions only the X‑Serie Gateway firmware version V6_00_05; no other vendors or product variants are listed.
Risk and Exploitability
The CVSS score is 6.3, indicating a medium severity, but the impact is high due to write access to key configuration directories. The exploit requires authentication with a Standard‑role account, a common role on the gateway. Because the vulnerability is remotely exploitable through a web interface, the risk is significant. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers with legitimate credentials can leverage this flaw to change gateway behavior.
OpenCVE Enrichment