MBS Universal Gateways Stack Buffer Overflow Vulnerability Leading to Root Access

Vulnerability

A stack buffer overflow vulnerability has been identified in the MBS Universal Gateways (UGW) web GUI and the underlying firmware, affecting version V6_0_0_5 and earlier. This vulnerability allows remote attackers with user privileges to execute arbitrary code with root privileges, potentially leading to a full system compromise. The issue arises from insufficient input validation and a lack of bounds checking in several CGI methods, which can be exploited by authorized attackers to manipulate memory and execute malicious code.

Impact

Exploitation of this vulnerability allows authenticated attackers to execute arbitrary code with root privileges on the affected UGW devices, leading to a full system compromise.

Remediation

Users are advised to update the affected products to firmware version V6_0_0_7, available at the MBS Firmware Update page.

Added: Jun 3, 2026, 1:19 PM
Updated: Jun 3, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.