CVE-2026-75165
Received Received - Intake

Authenticated Information Disclosure in MBS-Solutions X-Serie Gateway

Vulnerability report for CVE-2026-75165, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mbs-solutions x-serie_gateway 6.00.05

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the MBS-Solutions X-Serie Gateway firmware V6_00_05. It allows a remote authenticated user with low privileges to access hidden network diagnostic tools like ugw-ping and ugw-traceroute through /cgi-bin/wwwugw.cgi. These tools are not visible in the web interface.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized use of network diagnostic methods like ugw-ping or ugw-traceroute. Monitor CGI-bin access logs for /cgi-bin/wwwugw.cgi requests with these parameters. Inspect network traffic for unusual ping or traceroute activity originating from the gateway device.

Impact Analysis

An attacker with Standard role access could use this flaw to perform network diagnostics, potentially revealing sensitive network information such as IP addresses, routing paths, or device configurations. This could aid further attacks on the network.

Compliance Impact

The vulnerability allows unauthorized access to network diagnostic tools, potentially exposing sensitive network information. This could lead to violations of data protection requirements under GDPR and HIPAA by enabling unauthorized data collection or disclosure.

Mitigation Strategies

Immediately update the MBS-Solutions X-Serie Gateway firmware to the latest version. Restrict access to /cgi-bin/wwwugw.cgi by implementing strict ACLs. Disable low-privileged Standard role accounts until the issue is resolved. Monitor for suspicious activity and consider isolating the device if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75165. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart