CVE-2026-75161: Mbs-solutions X-Serie Gateway firmware vulnerability
Published Sep 4, 2026
·Updated
An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V60005 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root.
Affected Software
1 affected component
Mbs-solutions X-Serie Gateway firmware=V6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be able to authenticate to the gateway with an account assigned the low-privileged Standard role. No unauthenticated exploitation is described.
2
What is the impact after successful exploitation?
A Standard-role user can inject arbitrary code into the dpcheck utility. Because dpcheck is executed as root, the injected code runs with root privileges.
3
Which firmware version is identified as affected?
The issue is reported in MBS-Solutions X-Serie Gateway firmware V6_00_05.