CVE-2026-75168: Mbs-solutions X-Serie Gateway firmware vulnerability
An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V60005 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to the gateway and have the low-privileged Standard role. No higher-privileged account is required according to the available information.
What access does exploitation provide?
The attacker can write arbitrary content to files under /uxx/config/ and /ugw/config/ through the ugw-editfile method in /cgi-bin/wwwugw.cgi.
How can I determine whether a device is affected?
The affected firmware version identified is MBS-Solutions X-Serie Gateway firmware V6_00_05. Confirm whether the gateway exposes /cgi-bin/wwwugw.cgi and whether Standard-role users can access the ugw-editfile method.