An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
An attacker obtains or analyzes the device firmware image and finds a hard-coded default password within it. Since this password is identical for all instances of the product and requires no authentication or privileges to extract, anyone with access to the firmware image can recover it. The attacker then uses the obtained password to log into the target device over the network.
An attacker gains full access to all affected devices, which may include device takeover, configuration modification, disruption of industrial network operations, or further lateral movement within OT/ICS infrastructure.
Apply patches available from the manufacturer according to the references provided. As temporary security measures, isolate devices from untrusted networks, restrict access to management interfaces using a firewall, and monitor unauthorized login attempts. Details are available at: https://www.certvde.com/en/advisories/VDE-2026-039/
MBS-Solutions Universal Gateway Firmware, MBS-Solutions Double-A Profibus, MBS-Solutions Double-A X-Link, MBS-Solutions Double-X CAN, MBS-Solutions Double-X DALI — versions indicated in manufacturer references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMbs Solutions Double A Profibus
HWMbs-Solutionsall versionsMbs Solutions Double A X Link
HWMbs-Solutionsall versionsMbs Solutions Double X Can
HWMbs-Solutionsall versionsMbs Solutions Double X Dali
HWMbs-Solutionsall versionsMbs Solutions Double X Knx
HWMbs-Solutionsall versionsMbs Solutions Double X Lon
HWMbs-Solutionsall versionsMbs Solutions Double X M Bus
HWMbs-Solutionsall versionsMbs Solutions Double X Profinet
HWMbs-Solutionsall versionsMbs Solutions Double X X Link
HWMbs-Solutionsall versionsMbs Solutions Single A
HWMbs-Solutionsall versionsMbs Solutions Single X
HWMbs-Solutionsall versionsMbs Solutions Triple X Knx\+dali
HWMbs-Solutionsall versionsMbs Solutions Triple X Knx\+lon
HWMbs-Solutionsall versionsMbs Solutions Triple X Knx\+m Bus
HWMbs-Solutionsall versionsMbs Solutions Triple X Profinet\+dali
HWMbs-Solutionsall versionsMbs Solutions Triple X Profinet\+knx
HWMbs-Solutionsall versionsMbs Solutions Triple X Profinet\+lon
HWMbs-Solutionsall versionsMbs Solutions Triple X Profinet\+m Bus
HWMbs-Solutionsall versionsMbs Solutions Universal Gateway Firmware
OSMbs-Solutions< 6_00_07
Related vulnerabilities
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to...
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due ...
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to i...
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to in...
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due t...