Executive brief
The MBS X-Serie Gateway is a universal industrial gateway used in building automation and critical infrastructure to translate between different communication protocols (KNX, PROFIBUS, DALI, etc.). A vulnerability in the user management feature allows an authenticated attacker with a low-level "Standard" user account to reset passwords for any other user, potentially including administrative accounts, leading to unauthorized access and system compromise.
Technical details
This is a broken access control vulnerability in the ugw-usr-edit method of the /cgi-bin/wwwugw.cgi CGI script. The flaw fails to properly validate that a Standard-role user can only modify their own account; instead, it allows changing the password of arbitrary accounts. The vulnerability is accessible to any authenticated user via HTTP/HTTPS on the built-in web server. An attacker with valid Standard credentials can exploit this to escalate privileges by taking over higher-privileged accounts (such as administrative accounts), gaining full control of the gateway device and its automation functions. Firmware version V6_00_05 and earlier are affected.
Affected products
- MBS X-Serie Gateway V6_00_05 and earlier
Timeline
- 2026-09-04: disclosed