CRITICAL🇵🇱 Wersja polska

CVE-2026-35075

CVSS 9.3v4.0pub. 2026-06-03upd. 2026-07-22

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

🤖 AI Analysis
How it works

An attacker obtains or analyzes the device firmware image and finds a hard-coded default password within it. Since this password is identical for all instances of the product and requires no authentication or privileges to extract, anyone with access to the firmware image can recover it. The attacker then uses the obtained password to log into the target device over the network.

Impact

An attacker gains full access to all affected devices, which may include device takeover, configuration modification, disruption of industrial network operations, or further lateral movement within OT/ICS infrastructure.

Mitigation & patch

Apply patches available from the manufacturer according to the references provided. As temporary security measures, isolate devices from untrusted networks, restrict access to management interfaces using a firewall, and monitor unauthorized login attempts. Details are available at: https://www.certvde.com/en/advisories/VDE-2026-039/

Who is affected

MBS-Solutions Universal Gateway Firmware, MBS-Solutions Double-A Profibus, MBS-Solutions Double-A X-Link, MBS-Solutions Double-X CAN, MBS-Solutions Double-X DALI — versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mbs Solutions Double A Profibus

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double A X Link

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X Can

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X Dali

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X Knx

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X Lon

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X M Bus

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X Profinet

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Double X X Link

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Single A

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Single X

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Knx\+dali

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Knx\+lon

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Knx\+m Bus

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Profinet\+dali

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Profinet\+knx

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Profinet\+lon

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Triple X Profinet\+m Bus

    HW
    Mbs-Solutions
    all versions
  • Mbs Solutions Universal Gateway Firmware

    OS
    Mbs-Solutions
    < 6_00_07
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-35076HIGH7.2same product

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to...

CVE-2026-35077HIGH7.2same product

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due ...

CVE-2026-35078HIGH7.2same product

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to i...

CVE-2026-35079HIGH7.2same product

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to in...

CVE-2026-35080HIGH7.2same product

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due t...