ZeroHour

CVE-2026-75169

niche

Authenticated Arbitrary File Upload in MBS-Solutions X-Serie Gateway

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

MBS-Solutions X-Serie Gateway firmware V6_00_05 contains an unrestricted file upload flaw (CWE-434) in its /cgi-bin/ugwupload.cgi CGI endpoint. A remote attacker who already holds an authenticated Admin account can upload files with fully attacker-controlled content to hardcoded paths on the device. Because the destination paths are hardcoded, the upload can overwrite or plant files in sensitive locations, which per the CVSS 8.8 (high) rating can lead to high-impact confidentiality, integrity, and availability effects depending on the path targeted. Organizations running X-Serie Gateway firmware V6_00_05 are affected, particularly any deployment whose administrative web interface is reachable from untrusted networks. There is currently no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.5% (41st percentile), so no active exploitation is known.

What to do: Restrict access to the gateway's web/CGI interface (including /cgi-bin/ugwupload.cgi) to trusted management networks and review which accounts hold Admin rights. Check the hardcoded upload destination paths on affected devices for unexpected or tampered files. Upgrade to a fixed firmware release from MBS-Solutions when available (the fixed version is not stated in the available data), and monitor upload activity on ugwupload.cgi in the meantime.

Affected
MBS-Solutions X-Serie Gatewayfirmware V6_00_05 (the only version named in the advisory; other firmware versions may be affected but are not confirmed in the available data)
Estimated exposure
nicheon the order of thousands of installations, mostly in German-speaking organizations; unknown share internet-exposed — MBS-Solutions X-Serie gateways are a niche line of on-prem workforce-management/time-attendance integration devices sold primarily in the German DACH market, with no public scan or install-base counts available, and the CGI admin endpoint…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.

Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.