Junglewise Threat Intelligence

CVE-2026-75160: MBS X-Serie Gateway privilege escalation in web endpoints

CVE-2026-75160 · Severity: critical · CVSS 9.1 · Published 2026-09-04

Technologies: MBS GmbH X-Serie Gateway. Vendors: MBS GmbH.

Executive brief

The MBS X-Serie Gateway is a building automation device used to integrate and translate between different industrial communication protocols in facility management systems. A vulnerability in the gateway's firmware allows remote attackers to escalate privileges via exposed web endpoints, potentially granting unauthorized access to critical building infrastructure controls and configuration data.

Technical details

A privilege escalation vulnerability exists in the MBS X-Serie Gateway Firmware version V6_00_05 affecting the CGI endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. The vulnerability allows a remote, unauthenticated attacker to escalate privileges through these web-accessible endpoints without requiring prior authentication or user interaction. An attacker exploiting this flaw can achieve full administrative access to the gateway, enabling configuration tampering, protocol manipulation, or denial of service. The exact patch status and availability of firmware updates has not been disclosed in available advisory materials.

Affected products

  • MBS GmbH X-Serie Gateway V6_00_05

Timeline

  • 2026-09-04: disclosed

References

Related threats