Sceawere

Vulnerability Detail

CVE-2026-75160UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

X-Serie Gateway Privilege Escalation

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
5h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-09-04T16:17:57.827Z",
  "pubdate": "2026-09-04T16:17:57.827Z",
  "executiveSummary": "X-Serie Gateway Firmware V6_00_05 is susceptible to a privilege escalation vulnerability within its CGI-based administrative interfaces.\nThe vulnerability resides in the /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi endpoints, which fail to properly enforce access control mechanisms.\nA remote, unauthenticated or low-privileged attacker can exploit these endpoints to execute unauthorized operations, effectively bypassing existing security restrictions.\nThis vulnerability poses a critical risk as it allows unauthorized actors to gain elevated control over the device, potentially leading to full administrative compromise, data exfiltration, or modification of system configurations.\nGiven that these endpoints are network-accessible, the attack surface is exposed to any entity capable of reaching the gateway interface.\nThe exploitation does not require advanced persistent access, relying instead on the inherent flaws within the CGI processing logic of the firmware.",
  "technicalDetails": "The vulnerability is rooted in inadequate input validation and access control enforcement within the Common Gateway Interface (CGI) binaries /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. These scripts are responsible for handling gateway configuration management and file download operations, respectively.\nUnder normal operating conditions, these endpoints are intended to restrict specific administrative functions to authenticated sessions with sufficient authorization levels. However, the firmware's implementation fails to verify session tokens or user identity headers before processing requests sent to these specific paths.\nThe attack flow commences when a remote attacker sends a crafted HTTP request to either /cgi-bin/wwwugw.cgi or /cgi-bin/ugwdownload.cgi. Because the CGI scripts perform insufficient session validation, the backend process proceeds to interpret the request parameters as legitimate administrative commands.\nFor /cgi-bin/wwwugw.cgi, the attacker can manipulate internal configuration state or trigger system-level tasks that typically require administrative privilege. The script fails to sanitize the input parameters, allowing for command injection or logical overrides that force the application to perform actions outside the intended scope of a restricted user or an unauthenticated session.\nSimilarly, /cgi-bin/ugwdownload.cgi serves as an entry point for unauthorized information disclosure. By exploiting this endpoint, an attacker can bypass authorization logic to trigger arbitrary file downloads, which may include sensitive configuration files, system logs, or security-critical credentials that are otherwise inaccessible to non-administrative entities.\nThe root cause is the reliance on flawed authentication checks within the CGI application logic. By bypassing the intended front-end checks, the attacker directly interacts with the backend processing functions of the X-Serie Gateway. The firmware treats the incoming HTTP requests as trusted, thereby granting the attacker the same execution context as an administrative user.\nPost-exploitation impact is severe, as the attacker can manipulate the gateway's routing, firewall rules, or VPN credentials, potentially allowing for the establishment of a persistent backdoor or enabling man-in-the-middle attacks against traffic passing through the gateway. This lack of secondary validation effectively renders the gateway's administrative boundary moot for any attacker capable of reaching the CGI endpoints over the network."
}
CVE-2026-75160: X-Serie Gateway Privilege Escalation (CRITICAL Severity, CVSS: 9.1) - Sceawere