Arbitrary File Deletion in the ugw-logstop Method
CVE:
CVE-2026-35078
Product: MBS / UGW Universal Gateway (A-Series, X-Series)
Severity: High 8.1
Published: 03.06.2026
Advisory:
Read the advisory
The ugw-logstop method of the MBS UGW web GUI (firmware before V6_00_07) validates user-controlled input insufficiently (CWE-73). A remote attacker with user privileges can delete arbitrary local files.