Executive brief
The MBS X-Serie Gateway is a universal networking appliance used in building automation to translate between different communication protocols (KNX, PROFIBUS, DALI, etc.) and manage facility systems. A vulnerability in the firmware's web-based configuration interface allows an authenticated user with a basic "Standard" role to overwrite critical configuration files, potentially disrupting gateway operations, modifying automated building controls, or establishing persistence on the device.
Technical details
The vulnerability is an arbitrary file write flaw in the ugw-editfile method of the /cgi-bin/wwwugw.cgi endpoint. An authenticated remote user with the low-privileged Standard role can write arbitrary content to files in the /uxx/config/ and /ugw/config/ directories without proper authorization checks. The attack requires valid authentication credentials but no additional privileges beyond the default Standard role. A successful exploit allows an attacker to modify gateway configuration, potentially disabling critical building automation functions, altering protocol translations, or compromising device integrity. Patches should be available from MBS-Solutions.
Affected products
- MBS-Solutions X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed