Stack-based Buffer Overflow in the bac-deviceobject Method
CVE:
CVE-2026-35083
Product: MBS / UGW Universal Gateway (A-Series, X-Series)
Severity: High 8.8
Published: 03.06.2026
Advisory:
Read the advisory
A stack-based buffer overflow (CWE-121) in the bac-deviceobject method of the MBS UGW web GUI (firmware before V6_00_07) allows a remote attacker with user privileges to gain full system access as root.