CVE-2026-75165: Mbs-solutions X-Serie Gateway firmware vulnerability
Published Sep 4, 2026
·Updated
An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V60005 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.
Affected Software
1 affected component
Mbs-solutions X-Serie Gateway firmware=V6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker must be remotely authenticated with a low-privileged account assigned the Standard role.
2
What functionality can be accessed?
The affected CGI endpoint permits Standard-role users to invoke the hidden ugw-ping and ugw-traceroute network diagnostic methods, even though those methods are not available through the web interface.
3
What is the impact of successful exploitation?
An attacker can obtain sensitive information through the exposed network diagnostic functionality.