Executive brief
The MBS X-Serie Gateway is a universal industrial communication gateway used to bridge different building automation protocols and reduce integration costs. An authenticated attacker with basic user privileges can read arbitrary files from the gateway's filesystem through a web interface vulnerability, potentially exposing sensitive configuration data, credentials, or system information critical to facility operations.
Technical details
The vulnerability is an arbitrary file read flaw in the /cgi-bin/ugwdownload.cgi endpoint of MBS X-Serie Gateway firmware V6_00_05. An authenticated remote attacker with a low-privileged Standard role can exploit an unsafe file parameter to retrieve arbitrary files from the device filesystem. The attack requires valid authentication credentials but no elevated privileges. The vulnerability allows full filesystem disclosure, which could lead to exposure of configuration files, private keys, or other sensitive data stored on the gateway. A security update addressing this issue is required.
Affected products
- MBS GmbH X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed