CVE-2026-75164: Mbs-solutions X-Serie Gateway firmware vulnerability
Published Sep 4, 2026
·Updated
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V60005 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.
Affected Software
1 affected component
Mbs-solutions X-Serie Gateway firmware=V6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker must be able to authenticate to the gateway with an account assigned the low-privileged Standard role. The issue is exploitable remotely by such an authenticated user.
2
What is the impact of successful exploitation?
A Standard-role user can retrieve arbitrary files from the device filesystem through the file query string parameter handled by the ugwdownload.cgi endpoint.
3
Which firmware version is identified as affected?
The reported affected version is MBS-Solutions X-Serie Gateway firmware V6_00_05.