CVE-2026-75166

Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 16:17

Updated : 2026-09-09 20:20


NVD link : CVE-2026-75166

Mitre link : CVE-2026-75166

CVE.ORG link : CVE-2026-75166


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-276

Incorrect Default Permissions