CVE-2026-75169
nicheAuthenticated Arbitrary File Upload in MBS-Solutions X-Serie Gateway
MBS-Solutions X-Serie Gateway firmware V6_00_05 contains an unrestricted file upload flaw (CWE-434) in its /cgi-bin/ugwupload.cgi CGI endpoint. A remote attacker who already holds an authenticated Admin account can upload files with fully attacker-controlled content to hardcoded paths on the device. Because the destination paths are hardcoded, the upload can overwrite or plant files in sensitive locations, which per the CVSS 8.8 (high) rating can lead to high-impact confidentiality, integrity, and availability effects depending on the path targeted. Organizations running X-Serie Gateway firmware V6_00_05 are affected, particularly any deployment whose administrative web interface is reachable from untrusted networks. There is currently no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.5% (41st percentile), so no active exploitation is known.
What to do: Restrict access to the gateway's web/CGI interface (including /cgi-bin/ugwupload.cgi) to trusted management networks and review which accounts hold Admin rights. Check the hardcoded upload destination paths on affected devices for unexpected or tampered files. Upgrade to a fixed firmware release from MBS-Solutions when available (the fixed version is not stated in the available data), and monitor upload activity on ugwupload.cgi in the meantime.
| MBS-Solutions X-Serie Gateway | firmware V6_00_05 (the only version named in the advisory; other firmware versions may be affected but are not confirmed in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.