MBS Vulnerabilities and Affected Products
Vulnerabilities associated with Double-X DALI.
Products
Clear product- UBR-01 Mk II15 vulnerabilities
- UBR-0215 vulnerabilities
- UBR-LON15 vulnerabilities
- Double-A Profibus11 vulnerabilities
- Double-A x-link11 vulnerabilities
- Double-X CAN11 vulnerabilities
- Double-X DALI11 vulnerabilities
- Double-X KNX11 vulnerabilities
- Double-X LON11 vulnerabilities
- Double-X M-Bus11 vulnerabilities
- Double-X PROFINET11 vulnerabilities
- Double-X x-link11 vulnerabilities
- Single-A11 vulnerabilities
- Single-X11 vulnerabilities
- Triple-X KNX+DALI11 vulnerabilities
- Triple-X KNX+LON11 vulnerabilities
- Triple-X KNX+M-Bus11 vulnerabilities
- Triple-X PROFINET+DALI11 vulnerabilities
- Triple-X PROFINET+KNX11 vulnerabilities
- Triple-X PROFINET+LON11 vulnerabilities
- Triple-X PROFINET+M-Bus11 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-35085HIGH | Stack buffer overflow in method gdv-serverconfigA remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. CWE-121Jun 3, 2026 | CVSS8.7v4.0 | EPSS0.466% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35084HIGH | Stack buffer overflow in method dali-devconfigA remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. CWE-121Jun 3, 2026 | CVSS8.7v4.0 | EPSS0.456% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35083HIGH | Stack buffer overflow in method bac-deviceobjectA remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. CWE-121Jun 3, 2026 | CVSS8.7v4.0 | EPSS0.456% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35082HIGH | Local file inclusion vulnerability and deletion in ugw-logread methodThe ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. CWE-22Jun 3, 2026 | CVSS8.7v4.0 | EPSS0.494% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35081HIGH | Arbitrary process termination vulnerability in method ugw-logstopThe ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. CWE-20Jun 3, 2026 | CVSS7.2v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35080HIGH | Arbitrary file delete vulnerability in method ugw-restoreinfoThe ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73Jun 3, 2026 | CVSS7.2v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35079HIGH | Arbitrary file delete vulnerability in method ugw-restoreThe ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73Jun 3, 2026 | CVSS7.2v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35078HIGH | Arbitrary file delete vulnerability in method ugw-logstopThe ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73Jun 3, 2026 | CVSS7.2v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35077HIGH | Arbitrary file delete vulnerability in method ugw-delete-fileThe ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73Jun 3, 2026 | CVSS7.2v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35076HIGH | Arbitrary file delete vulnerability in method bac-scanresultThe bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. CWE-73Jun 3, 2026 | CVSS7.2v4.0 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-35075CRITICAL | Hardcoded default Password for Service AccountAn unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. CWE-1393Jun 3, 2026 | CVSS9.3v4.0 | EPSS0.466% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |