Description
An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.
Published: 2026-09-04
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Upload
Action: Patch
AI Analysis

Impact

An authenticated user with an Admin role can upload any file to the MBS‑Solutions X‑Serie Gateway using the CGI script at /cgi-bin/ugwupload.cgi. Because the destination paths are hardcoded and no file type checks are performed, the attacker can place executable or web‑accessible files on the device, enabling the execution of arbitrary code or the hosting of malicious payloads. The lack of input validation and authentication checks changes the confidentiality, integrity, and availability of the system if exploited.

Affected Systems

The vulnerability affects the MBS‑Solutions X‑Serie Gateway firmware version V6_00_05. No other vendor or product versions are listed as affected.

Risk and Exploitability

The EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 8.8 highlights high severity. However, the vulnerability still requires only a remote authenticated Admin account, which is commonly granted to legitimate users. Because the vulnerability permits uploading arbitrary files to hardcoded locations without type checks, an attacker can place executable or web‑accessible files, enabling remote code execution or a web‑shell. The lack of directory traversal or path validation confines the attack to the predefined upload locations, but the ability to place malicious files there is enough to compromise the system. The risk remains high due to the privileged attacker role and the unfiltered upload capability. The issue is not listed in CISA KEV.

Generated by OpenCVE AI on September 10, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest firmware update from MBS‑Solutions that removes the vulnerable upload endpoint.
  • If an update is not yet available, revoke remote Admin privileges or disable the gateway’s network access until remediation is applied.
  • Block access to the /cgi-bin/ugwupload.cgi URL via firewall rules or router ACLs to prevent uploads.
  • Enable logging and monitor for attempted access to the upload endpoint to detect any ongoing exploitation attempts.

Generated by OpenCVE AI on September 10, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Arbitrary File Upload in MBS‑Solutions X‑Serie Gateway Firmware

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Arbitrary File Upload in MBS‑Solutions X‑Serie Gateway
Weaknesses CWE-284

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Mbs-solutions
Mbs-solutions x-serie Gateway
Vendors & Products Mbs-solutions
Mbs-solutions x-serie Gateway

Fri, 04 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Authenticated Arbitrary File Upload in MBS‑Solutions X‑Serie Gateway
Weaknesses CWE-284
CWE-434

Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.
References

Subscriptions

Mbs-solutions X-serie Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-08T14:11:03.532Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75169

cve-icon Vulnrichment

Updated: 2026-09-08T14:10:10.936Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T16:17:58.937

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-75169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:15:14Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type