Executive brief
The MBS X-Serie Gateway is a universal protocol translation device used in building automation systems to bridge communication between different industrial protocols. A permission misconfiguration allows a low-privileged service account to run the packet capture tool tcpdump with root privileges, enabling attackers with local access to execute arbitrary commands with full system control. This impacts critical infrastructure environments that depend on these gateways for operational continuity.
Technical details
This vulnerability is an insecure permission issue in the gateway firmware (V6_00_05) where tcpdump is configured to run as root via privilege escalation, without proper access controls. An authenticated local attacker can leverage the tcpdump -z option (which allows command execution post-capture) to achieve arbitrary command execution with root privileges. The attack vector is local and requires prior authentication or service-level access to the device. A firmware patch correcting the sudoers configuration or removing the privilege escalation is likely required; the NVD entry was published on 2026-09-04 and there is no indication of active exploitation in the wild.
Affected products
- MBS-Solutions X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed