CVE-2026-35080: Arbitrary file delete vulnerability in method ugw-restoreinfo
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the ugw-restoreinfo method or remove its availability to non-administrative users until an official patch is available to prevent arbitrary local file deletion.
ugw-restoreinfo method enabled = false - Compensating control
Restrict access to the ugw-restoreinfo endpoint to trusted administrative accounts and trusted IP ranges using network controls (firewall, ACL, WAF). Block or limit user-level access to the functionality to reduce exposure.
- Operational
Audit system logs for signs of exploitation of ugw-restoreinfo, identify any arbitrarily deleted files, restore affected files from backups, and investigate impacted user accounts; rotate credentials if compromise is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35080?
The severity of CVE-2026-35080 is rated as high with a score of 7.2.
How do I fix CVE-2026-35080?
To fix CVE-2026-35080, ensure that the software is updated to the latest version provided by Mbs-solutions to mitigate the arbitrary file deletion vulnerability.
What type of attack does CVE-2026-35080 facilitate?
CVE-2026-35080 allows a remote attacker with user privileges to perform arbitrary file deletion due to insufficient input validation.
What software is affected by CVE-2026-35080?
CVE-2026-35080 affects Mbs-solutions Universal Gateway Firmware.
What are the potential impacts of exploiting CVE-2026-35080?
Exploiting CVE-2026-35080 can lead to unauthorized deletion of critical local files, potentially disrupting system operations.