MBS Universal Gateway Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability in the ugw-restore method allows remote attackers with user privileges to delete arbitrary local files on affected MBS Universal Gateway devices. This issue arises from inadequate validation of user-controlled input. The vulnerability affects several MBS Universal Gateway models running firmware versions prior to 6.0.0.7.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of local files on the affected device.

Remediation

Users are advised to update to MBS firmware version 6.0.0.7, available at the MBS Firmware Update page.

Added: Jun 3, 2026, 1:24 PM
Updated: Jun 3, 2026, 1:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.