Executive brief
MBS Universal Gateways, which are used to connect different communication protocols in building automation systems, contain a vulnerability in their web management interface. An attacker with basic user credentials can exploit this flaw to shut down critical system processes. This could lead to a loss of control over building automation systems, resulting in operational downtime or a denial of service for connected infrastructure.
Technical details
An improper input validation vulnerability (CWE-20) exists in the 'ugw-logstop' CGI method of the MBS Universal Gateway (UGW) web GUI. The vulnerability stems from insufficient validation of user-supplied input passed to the method, which is used to manage logging processes. A remote attacker with low-level user privileges can exploit this by sending a specially crafted network request to terminate arbitrary processes on the underlying operating system. This can lead to a significant denial-of-service condition or the disabling of security-critical services. The issue is resolved in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) A-Series Firmware < V6_0_0_7
- MBS GmbH Universal Gateway (UGW) X-Series Firmware < V6_0_0_7
Timeline
- 2026-06-03: advisory: Initial advisory published by CERT@VDE
- 2026-06-03: disclosed: CVE-2026-35081 published to NVD