CVE-2026-75166: MBS-Solutions X-Serie Gateway vulnerability
Published Sep 4, 2026
·Updated
Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V60005 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.
Affected Software
1 affected component
MBS-Solutions X-Serie Gateway=V6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated attacker who has access to the low-privileged service user account can exploit it. The issue provides a path from that account to root-level command execution.
2
What capability enables command execution?
The service user can run /usr/bin/tcpdump as root without a password. An attacker can leverage tcpdump's -z option to execute arbitrary commands with root privileges.
3
Which firmware version is identified as affected?
The reported affected firmware version is V6_00_05 for the MBS-Solutions X-Serie Gateway.