← Vulnerability feed

Vulnerability record · CVE-2026-35080 · published 3 June 2026

CVE-2026-35080: Mbs-solutions universal gateway firmware vulnerability

Mbs Solutions · Universal Gateway Firmware

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

7.2 CVSS 4.0 High EPSS 0.53% · top 57.6% CWE-73 · CWE-73
7.2CVSS 4.0 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Jul 2026Last modified by NVD

Description

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-35080 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-35075Mbs-solutions universal gateway firmware vulnerabilityAn unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.EPSS 0.59%8.7CVE-2026-35084Mbs-solutions universal gateway firmware stack-based buffer overflow vulnerabilityA remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.EPSS 0.58%8.7CVE-2026-35085Mbs-solutions universal gateway firmware stack-based buffer overflow vulnerabilityA remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.EPSS 0.58%8.7CVE-2026-35082Mbs-solutions universal gateway firmware path traversal vulnerabilityThe ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied …EPSS 0.68%8.7CVE-2026-35083Mbs-solutions universal gateway firmware stack-based buffer overflow vulnerabilityA remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.EPSS 0.58%7.2CVE-2026-35079Mbs-solutions universal gateway firmware vulnerabilityThe ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlle…EPSS 0.53%7.2CVE-2026-35081Mbs-solutions universal gateway firmware improper input validation vulnerabilityThe ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied…EPSS 0.53%7.2CVE-2026-35076Mbs-solutions universal gateway firmware vulnerabilityThe bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-contro…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2026-35080), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.