Executive brief
MBS Universal Gateways, which are used to connect different communication protocols in building automation systems, contain a vulnerability in their web management interface. An authenticated user can exploit this flaw to delete critical system files. This could lead to a complete loss of device configuration or cause the gateway to stop functioning, disrupting building operations.
Technical details
A vulnerability classified as External Control of File Name or Path (CWE-73) exists in the ugw-restore CGI method of MBS Universal Gateway (UGW) firmware. The issue stems from insufficient validation of user-supplied input within the web GUI's settings management. A remote attacker with valid user-level credentials can provide malicious path information to delete arbitrary files on the local filesystem. This can result in a denial of service or the destruction of sensitive configuration data. The vulnerability is addressed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware V6_0_0_7