« Volver al listado

Mbs-solutions

Mbs-solutions Universal Gateway Firmware: vulnerabilidades y CVE

Mbs-solutions Universal Gateway Firmware tiene 11 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses11
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-35085Alta (8.7)0.58%—3 jun 2026
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
CVE-2026-35084Alta (8.7)0.58%—3 jun 2026
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
CVE-2026-35083Alta (8.7)0.58%—3 jun 2026
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35082Alta (8.7)0.68%—3 jun 2026
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
CVE-2026-35081Alta (7.2)0.53%—3 jun 2026
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
CVE-2026-35080Alta (7.2)0.53%—3 jun 2026
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35079Alta (7.2)0.53%—3 jun 2026
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35078Alta (7.2)0.53%—3 jun 2026
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35077Alta (7.2)0.53%—3 jun 2026
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35076Alta (7.2)0.53%—3 jun 2026
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35075Crítica (9.3)0.59%—3 jun 2026
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services10
  2. T1059 Command and Scripting Interpreter3
  3. T1561.002 Disk Structure Wipe3
  4. T1565.002 Transmitted Data Manipulation2
  5. T1005 Data from Local System1
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Mbs-solutions