« Back to list

Mbs-solutions

Mbs-solutions Universal Gateway Firmware: vulnerabilities and CVEs

Mbs-solutions Universal Gateway Firmware has 11 published vulnerabilities, 11 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months11
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-35085High (8.7)0.58%—Jun 3, 2026
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
CVE-2026-35084High (8.7)0.58%—Jun 3, 2026
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
CVE-2026-35083High (8.7)0.58%—Jun 3, 2026
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35082High (8.7)0.68%—Jun 3, 2026
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
CVE-2026-35081High (7.2)0.53%—Jun 3, 2026
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
CVE-2026-35080High (7.2)0.53%—Jun 3, 2026
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35079High (7.2)0.53%—Jun 3, 2026
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35078High (7.2)0.53%—Jun 3, 2026
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35077High (7.2)0.53%—Jun 3, 2026
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35076High (7.2)0.53%—Jun 3, 2026
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35075Critical (9.3)0.59%—Jun 3, 2026
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services10
  2. T1059 Command and Scripting Interpreter3
  3. T1561.002 Disk Structure Wipe3
  4. T1565.002 Transmitted Data Manipulation2
  5. T1005 Data from Local System1
  6. T1078.001 Default Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Mbs-solutions