CVE-2026-75167
Received Received - Intake

Broken Access Control in MBS-Solutions X-Serie Gateway

Vulnerability report for CVE-2026-75167, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mbs-solutions x-serie_gateway 6.00.05

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a broken access control issue in the ugw-usr-edit method of the /cgi-bin/wwwugw.cgi file in MBS-Solutions X-Serie Gateway firmware version V6_00_05. It allows a remote authenticated user with a low-privileged Standard role to change the password of any account on the system.

Detection Guidance

To detect this vulnerability, check for unauthorized password changes in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi. Monitor logs for requests to this endpoint by low-privileged Standard role users. Verify account permissions and password reset activities.

Impact Analysis

An attacker with Standard role access could escalate privileges by changing passwords of higher-privileged accounts, potentially gaining full control over the gateway. This could lead to unauthorized access, system manipulation, or disruption of connected industrial or building automation systems.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and data protection, such as GDPR's principle of least privilege or HIPAA's access control safeguards. Unauthorized privilege escalation may lead to data breaches or unauthorized system changes, risking regulatory penalties.

Mitigation Strategies

Immediately update the X-Serie Gateway firmware to the latest version. Restrict access to the ugw-usr-edit method in /cgi-bin/wwwugw.cgi. Audit all user accounts for unauthorized changes and enforce strong password policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75167. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart