Executive brief
The MBS X-Serie Gateway is a universal industrial gateway used to bridge building automation protocols like KNX, PROFIBUS, and OPC-UA. A vulnerability in the gateway's web configuration interface allows any authenticated user—even those with basic Standard role permissions—to retrieve OPC-UA authentication credentials in plaintext. An attacker with valid (low-privilege) credentials could extract sensitive authentication tokens and use them to compromise OPC-UA systems connected to the gateway.
Technical details
The vulnerability is an information disclosure flaw in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS X-Serie Gateway firmware V6_00_05. A remote authenticated user with Standard role privileges can query the JSON API endpoint to retrieve OPC-UA authentication credentials in cleartext, exposing sensitive authentication material. The vulnerability requires valid authentication credentials to access the vulnerable endpoint, but the low-privileged Standard role is sufficient to exploit it. An attacker with valid user credentials could extract OPC-UA authentication secrets and pivot to compromise downstream building automation systems. Patch availability and fix details are not specified in the advisory.
Affected products
- MBS X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed
- 2026-09-04: advisory