CVE-2026-75163: Mbs-solutions X-Serie Gateway firmware vulnerability
Published Sep 4, 2026
·Updated
An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V60005 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role.
Affected Software
1 affected component
Mbs-solutions X-Serie Gateway firmware=V6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which users can retrieve the exposed version information?
Any authenticated user can retrieve it, including accounts assigned the low-privileged Standard role.
2
What access does an attacker need to exploit this issue?
The attacker must have valid authenticated access to the gateway. The disclosed information is returned by the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi.
3
What information is disclosed?
The response exposes detailed system version fields, including operatingsystem and gatewayversion.