CVE-2026-75160: X-Serie Gateway Firmware vulnerability
Published Sep 4, 2026
·Updated
An issue in X-Serie Gateway Firmware V60005 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
Affected Software
1 affected component
X-Serie Gateway Firmware=6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable, so an attacker needs network access to the affected gateway's exposed CGI endpoints. The available information does not state whether authentication is required.
2
Which firmware version is identified as affected?
The affected version identified in the available information is X-Serie Gateway Firmware V6_00_05.
3
Which components should be reviewed during triage?
Review exposure and access controls for /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi on X-Serie gateways running the identified firmware version. These are the endpoints associated with the privilege-escalation issue.