Vulnerability Description
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mbs-Solutions | Universal Gateway Firmware | < 6_00_07 |
| Mbs-Solutions | Double-A Profibus | - |
| Mbs-Solutions | Double-A X-Link | - |
| Mbs-Solutions | Double-X Can | - |
| Mbs-Solutions | Double-X Dali | - |
| Mbs-Solutions | Double-X Knx | - |
| Mbs-Solutions | Double-X Lon | - |
| Mbs-Solutions | Double-X M-Bus | - |
| Mbs-Solutions | Double-X Profinet | - |
| Mbs-Solutions | Double-X X-Link | - |
| Mbs-Solutions | Single-A | - |
| Mbs-Solutions | Single-X | - |
| Mbs-Solutions | Triple-X Knx\+Dali | - |
| Mbs-Solutions | Triple-X Knx\+Lon | - |
| Mbs-Solutions | Triple-X Knx\+M-Bus | - |
| Mbs-Solutions | Triple-X Profinet\+Dali | - |
| Mbs-Solutions | Triple-X Profinet\+Knx | - |
| Mbs-Solutions | Triple-X Profinet\+Lon | - |
| Mbs-Solutions | Triple-X Profinet\+M-Bus | - |
Related Weaknesses (CWE)
References
- https://www.certvde.com/en/advisories/VDE-2026-039/Vendor Advisory
FAQ
What is CVE-2026-35081?
CVE-2026-35081 is a vulnerability with a CVSS score of 8.1 (HIGH). The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
How severe is CVE-2026-35081?
CVE-2026-35081 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35081?
Check the references section above for vendor advisories and patch information. Affected products include: Mbs-Solutions Universal Gateway Firmware, Mbs-Solutions Double-A Profibus, Mbs-Solutions Double-A X-Link, Mbs-Solutions Double-X Can, Mbs-Solutions Double-X Dali.