CVE-2026-75167

A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 16:17

Updated : 2026-09-14 14:17


NVD link : CVE-2026-75167

Mitre link : CVE-2026-75167

CVE.ORG link : CVE-2026-75167


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control