SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75169

HIGH · CVSS 8.8 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An arbitrary file upload vulnerability exists in the /cgi-bin/ugwupload.cgi component of MBS-Solutions X-Serie Gateway firmware V6_00_05, enabling remote authenticated users with Admin privileges to upload files containing malicious content to predetermined locations. This could lead to unauthorized access, data manipulation, or system compromise. Organizations using this firmware should prioritize remediation to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75169
Severity
HIGH
CVSS
8.8
EPSS
0.49%

Original NVD Description

An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.