CVE-2026-75169: Mbs-solutions X-Serie Gateway firmware vulnerability
An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V60005 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to the gateway and have the Admin role. The issue is therefore most relevant where administrative access is exposed to untrusted users or where admin credentials could be compromised.
Which deployments are known to be affected?
The affected product identified is MBS-Solutions X-Serie Gateway firmware version V6_00_05. The provided information does not establish whether other firmware versions are affected.
What is the impact of successful exploitation?
An authenticated Admin user can upload files containing arbitrary content to hardcoded paths through the ugwupload.cgi endpoint. The provided information does not identify the specific paths or any resulting code-execution outcome.