Junglewise Threat Intelligence

CVE-2026-35082: MBS Universal Gateway path traversal in ugw-logread

CVE-2026-35082 · Severity: high · CVSS 8.8 · Published 2026-06-03

Technologies: MBS GmbH Universal Gateway X-Series Firmware, MBS GmbH Universal Gateway A-Series Firmware. Vendors: MBS GmbH.

Executive brief

MBS Universal Gateways are devices used to connect different communication protocols in building automation systems. A security flaw in the web management interface allows a logged-in user to bypass folder restrictions and access any file on the device's internal storage. This could lead to the exposure of sensitive configuration data or system credentials, potentially compromising the entire building management network.

Technical details

A path traversal vulnerability (CWE-22) exists in the 'ugw-logread' CGI method of the MBS Universal Gateway (UGW) web interface. The vulnerability is caused by insufficient validation of user-supplied input, which allows an attacker to use special characters (such as '../') to navigate outside of the intended log directory. An authenticated attacker with standard user privileges can exploit this over the network to read arbitrary files on the local filesystem. This can result in the disclosure of sensitive system information or configuration files. The issue is resolved in firmware version V6_0_0_7.

Affected products

  • MBS GmbH Universal Gateway (UGW) A-Series Firmware < V6_0_0_7
  • MBS GmbH Universal Gateway (UGW) X-Series Firmware < V6_0_0_7

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory
  • 2026-06-03: patched: Fixed in firmware version V6_0_0_7

References

Related threats