CVE-2026-75166
nicheAuthenticated privilege escalation to root via tcpdump in MBS X-Serie Gateway
CVE-2026-75166 is an insecure permission (sudo) misconfiguration in MBS-Solutions X-Serie Gateway firmware V6_00_05, under which the low-privileged service user is permitted to run /usr/bin/tcpdump as root without a password. An attacker who has obtained credentials for the service account, reachable over the network per the CVSS vector (AV:N/PR:L), can invoke tcpdump with the -z option to have it execute an arbitrary command as root. Successful exploitation therefore yields arbitrary command execution with root privileges, giving the attacker full control of the gateway with high impact on confidentiality, integrity and availability. Operators running X-Serie Gateway firmware V6_00_05 are affected; other firmware versions may carry the same sudo configuration, though only V6_00_05 is cited. There is currently no public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 0.2% probability of exploitation within 30 days, so no exploitation is known.
What to do: Restrict network access to the gateway's management/SSH service and ensure the low-privileged service account uses a strong, unique password, since compromise of that account is the prerequisite for root takeover. Audit the device configuration for passwordless sudo rules granting root access to /usr/bin/tcpdump (and check for tcpdump -z usage in logs), and contact MBS-Solutions for a corrected firmware release, as no fixed version is specified in the available data.
| MBS-Solutions X-Serie Gateway | firmware V6_00_05 (the only version cited in the advisory; other versions may share the same configuration but this is unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.
- Weakness
- CWE-269, CWE-276
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.