The ugw-logread method of the MBS UGW web GUI (firmware before V6_00_07) validates user-supplied input insufficiently (CWE-22). A remote attacker with user privileges can read arbitrary local files through path traversal.