CVE-2026-75167: Mbs-solutions X-Serie Gateway firmware vulnerability
Published Sep 4, 2026
·Updated
A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V60005 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts.
Affected Software
1 affected component
Mbs-solutions X-Serie Gateway firmware=V6_00_05
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker must be able to authenticate remotely with an account assigned the low-privileged Standard role.
2
What is the practical impact of successful exploitation?
A Standard-role user can change the passwords of arbitrary accounts, potentially allowing them to take over accounts with greater privileges.