Executive brief
MBS Universal Gateways are devices used to connect different communication protocols in building automation systems. A security vulnerability in the web management interface allows an authenticated user to delete important system files. This could lead to a complete loss of device configuration or cause the gateway to stop functioning, disrupting building operations.
Technical details
An arbitrary file deletion vulnerability (CWE-73) exists in the ugw-logstop CGI method of MBS Universal Gateway (UGW) A-Series and X-Series firmware. The flaw stems from insufficient validation of user-supplied input, allowing a remote attacker with low-level user privileges to specify and delete arbitrary local files on the filesystem. This is achieved via network requests to the web GUI's underlying CGI endpoints. Successful exploitation can lead to denial of service or loss of critical configuration data. The vulnerability is addressed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway A-Series Firmware < V6_0_0_7
- MBS GmbH Universal Gateway X-Series Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware version V6_0_0_7