Junglewise Threat Intelligence

CVE-2026-75161: MBS-Solutions X-Serie Gateway code injection in ugw-restart

CVE-2026-75161 · Severity: high · CVSS 8.8 · Published 2026-09-04

Executive brief

The MBS-Solutions X-Serie Gateway is a universal communication gateway used in building automation to connect different protocols and systems. A flaw in the gateway's web interface allows an authenticated user with basic privileges to inject malicious commands that execute with root-level access, potentially compromising the entire gateway and the critical infrastructure it manages.

Technical details

The vulnerability is a command injection flaw in the ugw-restart method of the /cgi-bin/wwwugw.cgi web interface in firmware version V6_00_05. An authenticated attacker with a low-privileged Standard role can craft malicious input that is passed unsanitized to the dpcheck system utility, which runs with root privileges. This allows arbitrary code execution in the context of the root user. The attack requires prior authentication to the web interface but does not require administrative privileges, and the injected commands execute on the underlying system with root access.

Affected products

  • MBS-Solutions X-Serie Gateway V6_00_05

Timeline

  • 2026-09-04: disclosed

References