Sceawere

Vulnerability Detail

CVE-2026-75163UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthorized Information Disclosure in Gateway

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
5h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-04T16:17:58.220Z",
  "pubdate": "2026-09-04T16:17:58.220Z",
  "executiveSummary": "The MBS-Solutions X-Serie Gateway firmware version V6_00_05 contains an information disclosure vulnerability within the cgi-bin/wwwugw.cgi script.\nSpecifically, the ugw-deviceinfo method fails to enforce proper authorization checks, allowing authenticated users with low-privileged Standard roles to retrieve sensitive system configuration metadata.\nThe leaked data includes specific operatingsystem and gatewayversion fields, which expose critical versioning details about the underlying system architecture.\nThis vulnerability is categorized as an Improper Authorization flaw, leading to sensitive information exposure.\nThe risk implication is primarily related to reconnaissance, as the disclosure of precise versioning information significantly assists an attacker in identifying known vulnerabilities (CVEs) associated with the specific operating system and firmware deployment, facilitating targeted exploit development.\nExploitation requires the attacker to possess valid credentials for a standard-privileged user account, after which they can perform arbitrary queries against the CGI interface to extract system state information.",
  "technicalDetails": "The vulnerability resides within the binary logic of /cgi-bin/wwwugw.cgi, which handles administrative and diagnostic requests via the gateway's web interface.\nAnalysis of the ugw-deviceinfo method confirms that the internal access control list (ACL) logic fails to validate the user session role prior to processing the request and returning the system object model.\nWhen a user with a Standard privilege level invokes this method, the backend application processes the request in the same manner as an administrator, subsequently serializing internal data structures to the HTTP response.\nThe technical flow of exploitation involves the attacker sending an HTTP POST or GET request directed at /cgi-bin/wwwugw.cgi with the argument specifying the ugw-deviceinfo method.\nBecause the web server does not terminate the request based on the caller's session permissions, the application logic proceeds to query the system's underlying configuration store.\nThe resulting output provides an unredacted view of internal fields, specifically the operatingsystem and gatewayversion parameters, which are intended only for administrative visibility.\nThe root cause is a broken access control mechanism in the dispatch handler for the CGI binary, which fails to verify the minimum required privilege level for diagnostic information retrieval.\nFrom a security perspective, this constitutes a significant reconnaissance vector; providing an attacker with exact version numbers allows for the precise mapping of the attack surface, enabling the search for secondary vulnerabilities applicable to the specific firmware build (V6_00_05) or the identified operating system kernel.\nThe vulnerability is limited to authenticated users; however, the lack of role-based segmentation ensures that even the lowest-tier user account can successfully bypass security boundaries to achieve persistent reconnaissance capabilities against the appliance."
}
CVE-2026-75163: Unauthorized Information Disclosure in Gateway (MEDIUM Severity, CVSS: 6.5) - Sceawere