CVE-2026-75164CWE-552
CVE-2026-75164
Medium · published September 4, 2026
What it is
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.
The record
Technical detail
- CVSS v3.1
- 6.5 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00404 · 33.7th percentile
- Weakness
- CWE-552 · Files or Directories Accessible to External Parties
- Published
- 2026-09-04T20:17Z
References (3)
EPSS history
Timeline