CVE-2026-75161
nicheAuthenticated Command Injection in MBS-Solutions X-Serie Gateway (wwwugw.cgi)
CVE-2026-75161 is a command injection flaw (CWE-77) in the ugw-restart method of the /cgi-bin/wwwugw.cgi endpoint in MBS-Solutions X-Serie Gateway firmware V6_00_05. A remote authenticated user holding only the low-privileged Standard role can inject arbitrary code that is passed into the dpcheck system utility, which executes as root. Successful exploitation therefore yields arbitrary command execution with root privileges on the gateway, giving the attacker full control of the appliance and anything it can reach. Only X-Serie Gateways running V6_00_05 (the sole version named in the advisory) are identified as affected; no other version ranges have been published in the available data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a roughly 0.5% probability of exploitation within 30 days (43rd percentile).
What to do: Inventory any MBS-Solutions X-Serie Gateways and check whether they run V6_00_05, then request a patched firmware from MBS-Solutions when available, since no fixed version is specified in the advisory. Until patched, restrict access to the gateway web interface (firewall rules, ACLs, or VPN), minimize and audit Standard-role accounts, and rotate low-privilege credentials, because any such account is sufficient for root-level compromise.
| MBS-Solutions X-Serie Gateway | firmware V6_00_05 (sole version named in the advisory; other affected or fixed versions not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root.
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.