Executive brief
MBS Universal Gateways, which connect different communication protocols in building automation systems, are vulnerable to a security flaw in their configuration interface. An attacker with basic user credentials can exploit this to take complete control of the device with administrative (root) privileges. This could lead to a total compromise of the building automation network, allowing unauthorized access to sensitive configuration data or disruption of building operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in the gdv-serverconfig CGI endpoint of the MBS Universal Gateway (UGW) web GUI. The vulnerability is caused by insufficient bounds checking on user-supplied input. A remote attacker with authenticated user-level privileges can exploit this flaw via network requests to execute arbitrary code with root privileges. This leads to a full system compromise, including the ability to read/delete files and cause a denial of service. The issue is fixed in firmware version V6_0_0_7.
Affected products
- MBS GmbH Universal Gateway (UGW) Firmware < V6_0_0_7
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory
- 2026-06-03: patched: Fixed in firmware V6_0_0_7