ZeroHour

CVE-2026-75160

Unauthenticated Privilege Escalation in X-Serie Gateway Firmware V6_00_05

CVSS 3.1
9.1 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-75160 is an improper privilege management flaw (CWE-269) in X-Serie Gateway Firmware V6_00_05 that allows a remote, unauthenticated attacker to escalate privileges. It is triggered by sending requests to the gateway's CGI endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi, which do not correctly enforce privilege boundaries. A successful attacker gains elevated access on the gateway with high impact to confidentiality and integrity, while availability is unaffected. Any deployment running the named V6_00_05 firmware is affected, with the greatest risk on gateways whose management interface is reachable from untrusted networks. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.

What to do: Inventory all gateways running firmware V6_00_05 and, until the vendor publishes a fixed version, restrict access to /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi and avoid exposing the gateway's management interface directly to the internet. Review device logs for unexpected requests to these endpoints and monitor for a vendor advisory or updated firmware.

Affected
X-Serie Gateway FirmwareV6_00_05 (the only version named as affected)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.