CVE-2026-75162: Mbs-solutions X-Serie Gateway firmware vulnerability
An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V60005 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response.
Affected Software
Event History
Frequently Asked Questions
Which users can retrieve the exposed OPC-UA credentials?
Any remote authenticated user can retrieve them, including an account assigned the low-privileged Standard role.
What must an attacker have to exploit this issue?
The attacker needs valid remote authentication to the gateway and access to the opcua-configuration method through the JSON API.
What information is exposed?
The JSON API response returns the configured OPC-UA authentication credentials in cleartext.
How can I determine whether a system is affected?
The affected firmware identified is X-Serie Gateway firmware V6_00_05. On that version, an authenticated request to the opcua-configuration method can be checked to determine whether the JSON response exposes OPC-UA credentials in cleartext.