Executive brief
Seiko Solutions SkyBridge MB-A100 and MB-A110 network gateways are affected by a security flaw that allows an authorized administrator to execute unauthorized system commands. If exploited, an attacker with administrative access could take full control of the device, leading to data theft, service disruption, or unauthorized network modifications. Because these products are no longer supported, no official security updates will be released, and users are advised to implement network restrictions to protect their systems.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Web management interface of Seiko Solutions SkyBridge MB-A100 and MB-A110 devices. The flaw stems from improper neutralization of special elements used in OS commands within the administrative WebUI. An attacker with high privileges (administrative access) can exploit this over the network to execute arbitrary OS commands on the underlying system. As the products have reached end-of-life, no patches are available. Recommended mitigations include changing default passwords, disabling WebUI access where possible, restricting WAN-side access via IP filtering, and deploying the devices within closed networks.
Affected products
- Seiko Solutions Inc. SkyBridge MB-A100/MB-A110 All versions
Timeline
- 2026-07-01: disclosed: Initial disclosure via JVN and Seiko Solutions advisory
- 2026-07-01: advisory: NVD publication date