CVE Feed

    Dashboard / CVE / CVE-2026-35079

    CVE-2026-35079

    The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

    Published:Jun 3, 2026
    Last Modified:Jun 8, 2026
    EPS:Jun 3, 2026
    EPSS Score:0.00105
    CVSS Score:8.1

    Affected Products

    Vendor
    Mbs
    Product
    Double-a Profibus
    Vendor
    Mbs
    Product
    Double-a X-link
    Vendor
    Mbs
    Product
    Double-x Can
    Vendor
    Mbs
    Product
    Double-x Dali
    Vendor
    Mbs
    Product
    Double-x Knx
    Vendor
    Mbs
    Product
    Double-x Lon
    Vendor
    Mbs
    Product
    Double-x M-bus
    Vendor
    Mbs
    Product
    Double-x Profinet
    Vendor
    Mbs
    Product
    Double-x X-link
    Vendor
    Mbs
    Product
    Double A Profibus Firmware
    Vendor
    Mbs
    Product
    Double A X Link Firmware
    Vendor
    Mbs
    Product
    Double X Can Firmware
    Vendor
    Mbs
    Product
    Double X Dali Firmware
    Vendor
    Mbs
    Product
    Double X Knx Firmware
    Vendor
    Mbs
    Product
    Double X Lon Firmware
    Vendor
    Mbs
    Product
    Double X M Bus Firmware
    Vendor
    Mbs
    Product
    Double X Profinet Firmware
    Vendor
    Mbs
    Product
    Double X X Link Firmware
    Vendor
    Mbs
    Product
    Single-a
    Vendor
    Mbs
    Product
    Single-x
    Vendor
    Mbs
    Product
    Single A Firmware
    Vendor
    Mbs
    Product
    Single X Firmware
    Vendor
    Mbs
    Product
    Triple-x Knx+dali
    Vendor
    Mbs
    Product
    Triple-x Knx+lon
    Vendor
    Mbs
    Product
    Triple-x Knx+m-bus
    Vendor
    Mbs
    Product
    Triple-x Profinet+dali
    Vendor
    Mbs
    Product
    Triple-x Profinet+knx
    Vendor
    Mbs
    Product
    Triple-x Profinet+lon
    Vendor
    Mbs
    Product
    Triple-x Profinet+m-bus
    Vendor
    Mbs
    Product
    Triple X Knx Dali Firmware
    Vendor
    Mbs
    Product
    Triple X Knx Lon Firmware
    Vendor
    Mbs
    Product
    Triple X Knx M Bus Firmware
    Vendor
    Mbs
    Product
    Triple X Profinet Dali Firmware
    Vendor
    Mbs
    Product
    Triple X Profinet Knx Firmware
    Vendor
    Mbs
    Product
    Triple X Profinet Lon Firmware
    Vendor
    Mbs
    Product
    Triple X Profinet M Bus Firmware
    Vendor
    Mbs-solutions
    Product
    Double-a Profibus
    Vendor
    Mbs-solutions
    Product
    Double-a X-link
    Vendor
    Mbs-solutions
    Product
    Double-x Can
    Vendor
    Mbs-solutions
    Product
    Double-x Dali
    Vendor
    Mbs-solutions
    Product
    Double-x Knx
    Vendor
    Mbs-solutions
    Product
    Double-x Lon
    Vendor
    Mbs-solutions
    Product
    Double-x M-bus
    Vendor
    Mbs-solutions
    Product
    Double-x Profinet
    Vendor
    Mbs-solutions
    Product
    Double-x X-link
    Vendor
    Mbs-solutions
    Product
    Single-a
    Vendor
    Mbs-solutions
    Product
    Single-x
    Vendor
    Mbs-solutions
    Product
    Triple-x Knx\+dali
    Vendor
    Mbs-solutions
    Product
    Triple-x Knx\+lon
    Vendor
    Mbs-solutions
    Product
    Triple-x Knx\+m-bus
    Vendor
    Mbs-solutions
    Product
    Triple-x Profinet\+dali
    Vendor
    Mbs-solutions
    Product
    Triple-x Profinet\+knx
    Vendor
    Mbs-solutions
    Product
    Triple-x Profinet\+lon
    Vendor
    Mbs-solutions
    Product
    Triple-x Profinet\+m-bus
    Vendor
    Mbs-solutions
    Product
    Universal Gateway Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High