CVE-2026-35079
Arbitrary file delete vulnerability in method ugw-restore
In short
A remote attacker with user credentials can delete any file on the system through the ugw-restore method because the system doesn't properly check what files they're trying to delete.
Technical detail
The ugw-restore method fails to validate user-supplied file paths, allowing an authenticated remote attacker to delete arbitrary files on the system. The vulnerability requires valid user privileges but lacks proper input sanitization on the file deletion parameter, resulting in potential loss of critical system or user data.
Summary generated and translated by AI from the official description.
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
MBS · Double-A ProfibusMBS · Double-A x-linkMBS · Double-X CANMBS · Double-X DALIMBS · Double-X KNXMBS · Double-X LONMBS · Double-X M-BusMBS · Double-X PROFINETMBS · Double-X x-linkMBS · Single-AMBS · Single-XMBS · Triple-X KNX+DALIMBS · Triple-X KNX+LONMBS · Triple-X KNX+M-BusMBS · Triple-X PROFINET+DALIMBS · Triple-X PROFINET+KNXMBS · Triple-X PROFINET+LONMBS · Triple-X PROFINET+M-BusWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →