Executive brief
The MBS X-Serie Gateway is a universal network gateway used to translate between different building automation protocols in critical infrastructure environments. A vulnerability in its web interface allows low-privileged users to invoke hidden diagnostic commands (ping and traceroute) that should not be accessible, potentially exposing network topology and system information to attackers with basic authentication access.
Technical details
The vulnerability exists in the /cgi-bin/wwwugw.cgi script of MBS X-Serie Gateway firmware V6_00_05. It permits authenticated users with the Standard role to invoke undocumented network diagnostic methods (ugw-ping, ugw-traceroute) that are hidden from the web UI. These methods are accessible without proper privilege escalation controls, allowing attackers with valid low-privilege credentials to execute network reconnaissance and information disclosure attacks. The issue affects authentication contexts where a Standard role user can make requests to this CGI endpoint without proper authorization checks for sensitive operations. Patches or updates should restrict access to these diagnostic methods or require higher privilege levels.
Affected products
- MBS X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed