Executive brief
MBS Universal Gateways are devices used in building automation to connect different communication protocols. A security flaw in the web management interface allows a logged-in user to delete any file on the device's local storage. This could lead to a loss of critical configuration data or cause the device to stop functioning correctly.
Technical details
An arbitrary file deletion vulnerability exists in the MBS Universal Gateway (UGW) web GUI. The flaw is located within the 'ugw-restoreinfo' CGI method, which fails to properly validate user-controlled input used in file path operations (CWE-73). A remote attacker with authenticated user privileges can exploit this by sending crafted requests to delete arbitrary local files on the filesystem. This can lead to a denial of service or loss of system integrity. The vulnerability is addressed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware version V6_0_0_7