ZeroHour

CVE-2026-75166

niche

Authenticated privilege escalation to root via tcpdump in MBS X-Serie Gateway

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-75166 is an insecure permission (sudo) misconfiguration in MBS-Solutions X-Serie Gateway firmware V6_00_05, under which the low-privileged service user is permitted to run /usr/bin/tcpdump as root without a password. An attacker who has obtained credentials for the service account, reachable over the network per the CVSS vector (AV:N/PR:L), can invoke tcpdump with the -z option to have it execute an arbitrary command as root. Successful exploitation therefore yields arbitrary command execution with root privileges, giving the attacker full control of the gateway with high impact on confidentiality, integrity and availability. Operators running X-Serie Gateway firmware V6_00_05 are affected; other firmware versions may carry the same sudo configuration, though only V6_00_05 is cited. There is currently no public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 0.2% probability of exploitation within 30 days, so no exploitation is known.

What to do: Restrict network access to the gateway's management/SSH service and ensure the low-privileged service account uses a strong, unique password, since compromise of that account is the prerequisite for root takeover. Audit the device configuration for passwordless sudo rules granting root access to /usr/bin/tcpdump (and check for tcpdump -z usage in logs), and contact MBS-Solutions for a corrected firmware release, as no fixed version is specified in the available data.

Affected
MBS-Solutions X-Serie Gatewayfirmware V6_00_05 (the only version cited in the advisory; other versions may share the same configuration but this is unconfirmed)
Estimated exposure
nicheunknown; plausibly hundreds to low thousands of deployed gateways at most — These are specialized industrial network appliances from a single small vendor that are typically deployed on internal plant or utility networks, and no public install-base counts or internet-exposure scan data are available, so only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.

Weakness
CWE-269, CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.