Executive brief
MBS Universal Gateways are devices used in building automation to connect different communication protocols. A security flaw in the web management interface allows a logged-in user to delete any file on the system. This could lead to a complete loss of configuration data or cause the device to stop functioning entirely.
Technical details
A path traversal or external control of file name vulnerability (CWE-73) exists in the 'ugw-delete-file' CGI method of the MBS Universal Gateway (UGW) web GUI. The component fails to properly validate user-supplied input before using it in file deletion operations. An authenticated remote attacker with standard user privileges can exploit this to delete arbitrary files on the local filesystem. This can result in a denial of service by removing critical system files or the loss of sensitive configuration data. The vulnerability is addressed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware version V6_0_0_7