Executive brief
MBS Universal Gateways are devices used in building automation to connect different communication protocols. A security flaw in the device's web management interface allows an authenticated user to take complete control of the system. An attacker could use this access to disrupt building operations, steal configuration data, or gain a permanent foothold on the network.
Technical details
A stack-based buffer overflow (CWE-121) exists in the 'dali-devconfig' CGI method of the MBS Universal Gateway (UGW) web GUI. The vulnerability is caused by insufficient input validation and a lack of bounds checking on user-supplied data. A remote attacker with valid user-level credentials can exploit this flaw via network requests to execute arbitrary code with root privileges. Successful exploitation results in a full system compromise, allowing for persistent access or denial of service. The issue is addressed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware version V6_0_0_7