ZeroHour

CVE-2026-75161

niche

Authenticated Command Injection in MBS-Solutions X-Serie Gateway (wwwugw.cgi)

CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-75161 is a command injection flaw (CWE-77) in the ugw-restart method of the /cgi-bin/wwwugw.cgi endpoint in MBS-Solutions X-Serie Gateway firmware V6_00_05. A remote authenticated user holding only the low-privileged Standard role can inject arbitrary code that is passed into the dpcheck system utility, which executes as root. Successful exploitation therefore yields arbitrary command execution with root privileges on the gateway, giving the attacker full control of the appliance and anything it can reach. Only X-Serie Gateways running V6_00_05 (the sole version named in the advisory) are identified as affected; no other version ranges have been published in the available data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a roughly 0.5% probability of exploitation within 30 days (43rd percentile).

What to do: Inventory any MBS-Solutions X-Serie Gateways and check whether they run V6_00_05, then request a patched firmware from MBS-Solutions when available, since no fixed version is specified in the advisory. Until patched, restrict access to the gateway web interface (firewall rules, ACLs, or VPN), minimize and audit Standard-role accounts, and rotate low-privilege credentials, because any such account is sufficient for root-level compromise.

Affected
MBS-Solutions X-Serie Gatewayfirmware V6_00_05 (sole version named in the advisory; other affected or fixed versions not specified)
Estimated exposure
nicheunknown; plausibly hundreds to a few thousand deployed gateway appliances — MBS-Solutions X-Serie Gateways are specialized integration appliances from a niche vendor, typically deployed inside customer networks rather than exposed at scale on the internet, and no public install-base counts or internet-exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root.

Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.