CVE-2026-35082
Local file inclusion vulnerability and deletion in ugw-logread method
In short
A remote user can read any file on the system because the ugw-logread method doesn't properly check what files it's allowed to access. This exposes sensitive data like passwords or configuration files.
Technical detail
The ugw-logread method lacks input validation on file path parameters, allowing path traversal attacks (CWE-22). An authenticated remote attacker can traverse directory structures to access arbitrary files on the system, resulting in unauthorized information disclosure.
Summary generated and translated by AI from the official description.
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
MBS · Double-A ProfibusMBS · Double-A x-linkMBS · Double-X CANMBS · Double-X DALIMBS · Double-X KNXMBS · Double-X LONMBS · Double-X M-BusMBS · Double-X PROFINETMBS · Double-X x-linkMBS · Single-AMBS · Single-XMBS · Triple-X KNX+DALIMBS · Triple-X KNX+LONMBS · Triple-X KNX+M-BusMBS · Triple-X PROFINET+DALIMBS · Triple-X PROFINET+KNXMBS · Triple-X PROFINET+LONMBS · Triple-X PROFINET+M-BusWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →