Use of Default Password for Service Account
CVE:
CVE-2026-35075
Product: MBS / UGW Universal Gateway (A-Series, X-Series)
Severity: Critical 9.8
Published: 03.06.2026
Advisory:
Read the advisory
The MBS UGW Universal Gateway firmware before V6_00_07 ships with a hard-coded default password for a service account (CWE-1393). An unauthenticated remote attacker can recover this password from a firmware image and thereby gain full access to all affected devices.