← Terug naar overzicht

CVE-2026-75160 is a privilege escalation vulnerability affecting X-Serie Gateway Firmware version V6_00_05. A remote attacker can exploit two specific CGI endpoints, /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi, to escalate privileges on the device. The vulnerability was reported by researcher SilviaMun and is documented on NVD. The affected product is manufactured by MBS Solutions, a company providing industrial gateway solutions. The issue allows unauthenticated or low-privileged remote attackers to gain elevated access, posing significant risk to network infrastructure and connected systems. No patch information is currently noted in the article. The vulnerability impacts firmware-level security of industrial or enterprise gateway hardware. Organizations using X-Serie Gateway devices running this firmware version should investigate exposure and apply mitigations. A proof-of-concept or vulnerability research repository is publicly available on GitHub, increasing the risk of exploitation.

Affected products

  • X-Serie Gateway Firmware V6_00_05

Related CVE's

  • CVE-2026-75160

IOC's

/cgi-bin/wwwugw.cgi, /cgi-bin/ugwdownload.cgi

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities