Executive brief
MBS Universal Gateways, which are used to connect different building automation systems, contain a hardcoded password within their firmware. An unauthorized person can extract this password from the device software and use it to gain full administrative control over any affected gateway. This could allow an attacker to disrupt building operations, access sensitive configuration data, or compromise the entire local network.
Technical details
The vulnerability (CWE-1393) exists in MBS Universal Gateway (UGW) A-Series and X-Series firmware versions prior to V6_0_0_7. A service account within the firmware uses a static, hardcoded password that can be recovered by analyzing the firmware image. Because this password is uniform across affected devices, an unauthenticated remote attacker can use it to gain unauthorized access with high privileges. This flaw significantly lowers the barrier for full system compromise. The vendor has released firmware version V6_0_0_7 to remediate this issue.
Affected products
- MBS GmbH Universal Gateway A-Series Firmware < V6_0_0_7
- MBS GmbH Universal Gateway X-Series Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Firmware version V6_0_0_7 released.