Executive brief
The MBS X-Serie Gateway is a universal gateway device used in building automation systems to bridge different communication protocols. A vulnerability allows an authenticated administrator to upload arbitrary files to the device, which could enable an attacker with admin credentials to deploy malicious code, disrupt automation services, or compromise the integrity of connected building systems.
Technical details
An arbitrary file upload vulnerability exists in the /cgi-bin/ugwupload.cgi endpoint of MBS X-Serie Gateway firmware version V6_00_05. The vulnerability allows an authenticated user with Admin role to upload files with arbitrary content to hardcoded paths on the device without proper validation. The attack requires valid administrative credentials and network access to the gateway's web interface. Successful exploitation could result in remote code execution or file system manipulation on the gateway device. Patches or updated firmware versions should be consulted from MBS-Solutions for remediation.
Affected products
- MBS-Solutions X-Serie Gateway V6_00_05
Timeline
- 2026-09-04: disclosed