MEDIUMVulnerability

CVE-2026-75165

An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-75165
signal_observed_at
2026-09-16T13:31:02+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-04T16:17:58.450
last_modified
2026-09-09T16:04:24.933

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75165 — Ninja Signal Threat Intelligence | Ninja Signal