Executive brief
The MBS X-Serie Gateway is a universal communication gateway used in building automation systems to bridge multiple industrial protocols. A flaw in its web interface allows any authenticated user, including those with limited privileges, to retrieve sensitive system information such as operating system and gateway version details that should be restricted to administrators, potentially aiding attackers in reconnaissance and planning targeted attacks.
Technical details
An information disclosure vulnerability exists in the ugw-deviceinfo method of the /cgi-bin/wwwugw.cgi endpoint on MBS-Solutions X-Serie Gateway firmware V6_00_05. The vulnerable component fails to enforce proper access controls, returning sensitive system version fields (operatingsystem, gatewayversion) to any authenticated user regardless of role. The attack requires network access to the gateway's web interface and valid credentials (including low-privileged Standard user accounts), but does not require user interaction. An attacker can exploit this to gather reconnaissance data about the target system, potentially identifying known vulnerabilities or planning further attacks. A patch or firmware update is expected from the vendor to enforce role-based access restrictions on this endpoint.
Affected products
- MBS-Solutions X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed