Executive brief
MBS Universal Gateways, which are used to connect different communication protocols in building automation systems, contain a security flaw in their web management interface. An authorized user can exploit this vulnerability to delete critical system files remotely. This could lead to a complete loss of device functionality, disruption of building management operations, and potential data loss.
Technical details
A vulnerability classified as External Control of File Name or Path (CWE-73) exists in the 'bac-scanresult' CGI method of the MBS Universal Gateway (UGW) web interface. The root cause is insufficient validation of user-supplied input, which allows a remote attacker with valid user-level credentials to specify and delete arbitrary files on the local filesystem. This can be used to disrupt system operations or delete configuration data. The vulnerability is addressed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) A-Series Firmware < V6_0_0_7
- MBS GmbH Universal Gateway (UGW) X-Series Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware version V6_0_0_7