CVE-2026-35077
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
03/06/2026
Last modified:
22/07/2026
Description
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mbs-solutions:universal_gateway_firmware:*:*:*:*:*:*:*:* | 6_00_07 (excluding) | |
| cpe:2.3:h:mbs-solutions:double-a_profibus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-a_x-link:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_can:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_dali:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_knx:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_lon:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_m-bus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_profinet:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:double-x_x-link:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:single-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:single-x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:triple-x_knx\+dali:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:triple-x_knx\+lon:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mbs-solutions:triple-x_knx\+m-bus:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



