Junglewise Threat Intelligence

CVE-2026-35083: MBS Universal Gateway stack buffer overflow in web GUI

CVE-2026-35083 · Severity: high · CVSS 8.8 · Published 2026-06-03

Technologies: MBS GmbH Universal Gateway Firmware. Vendors: MBS GmbH.

Executive brief

MBS Universal Gateways, which are used to connect different communication protocols in building automation systems, are vulnerable to a security flaw in their web management interface. An attacker with basic user credentials can exploit this weakness to take complete control of the device with administrative (root) privileges. This could allow an unauthorized party to disrupt building operations, access sensitive configuration data, or use the device as a foothold in the corporate network.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the web-based graphical user interface (GUI) of MBS Universal Gateway (UGW) devices. The flaw is caused by insufficient bounds checking on user-supplied input within certain CGI methods. A remote attacker with valid user-level authentication can exploit this vulnerability by sending specially crafted network requests to the affected CGI endpoints. Successful exploitation allows for arbitrary code execution with root privileges, leading to full system compromise. The vulnerability is addressed in firmware version V6_0_0_7.

Affected products

  • MBS GmbH Universal Gateway (UGW) Firmware < V6_0_0_7

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory
  • 2026-06-03: patched: Fixed in firmware version V6_0_0_7

References

Related threats