Impact
An authenticated user with an Admin role can upload any file to the MBS‑Solutions X‑Serie Gateway using the cgi script at /cgi-bin/ugwupload.cgi. Because the destination paths are hardcoded and no file type checks are performed, the attacker can place executable or web‑accessible files on the device, enabling the execution of arbitrary code or the hosting of malicious payloads. The lack of input validation and authentication checks changes the confidentiality, integrity, and availability of the system if exploited.
Affected Systems
The vulnerability affects the MBS‑Solutions X‑Serie Gateway firmware version V6_00_05. No other vendor or product versions are listed as affected.
Risk and Exploitability
No EPSS score is available and the issue is not listed in CISA KEV, so a precise exploitation probability is unknown. However, the vulnerability requires only a remote authenticated Admin account, a capability that is typically granted to legitimate users. The absence of directory traversal or path validation limits the attack surface to the predefined upload locations, but the ability to place malicious files in those locations is sufficient for remote code execution or web‑shell establishment. The severity is therefore likely high given the privileged nature of the attacker role and the unfiltered upload capability.
OpenCVE Enrichment