Impact
An authenticated user with an Admin role can upload any file to the MBS‑Solutions X‑Serie Gateway using the CGI script at /cgi-bin/ugwupload.cgi. Because the destination paths are hardcoded and no file type checks are performed, the attacker can place executable or web‑accessible files on the device, enabling the execution of arbitrary code or the hosting of malicious payloads. The lack of input validation and authentication checks changes the confidentiality, integrity, and availability of the system if exploited.
Affected Systems
The vulnerability affects the MBS‑Solutions X‑Serie Gateway firmware version V6_00_05. No other vendor or product versions are listed as affected.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 8.8 highlights high severity. However, the vulnerability still requires only a remote authenticated Admin account, which is commonly granted to legitimate users. Because the vulnerability permits uploading arbitrary files to hardcoded locations without type checks, an attacker can place executable or web‑accessible files, enabling remote code execution or a web‑shell. The lack of directory traversal or path validation confines the attack to the predefined upload locations, but the ability to place malicious files there is enough to compromise the system. The risk remains high due to the privileged attacker role and the unfiltered upload capability. The issue is not listed in CISA KEV.
OpenCVE Enrichment