MBS Universal Gateway Flaws Threaten Building Automation Networks
AdvisoryMBS Universal GatewayOur summary
MBS GmbH disclosed multiple critical security issues in its MBS Universal Gateway devices affecting firmware version V6_0_0_5 and earlier, including unauthenticated access via a default credential weakness tracked as CVE-2026-35075 (CVSS 9.8) and remotely exploitable stack buffer overflow problems tracked as CVE-2026-35085, CVE-2026-35084, and CVE-2026-35083. The flaws could allow attackers to obtain full root control and, in some cases, read sensitive logs, placing smart building perimeter networks at risk. Administrators should update affected gateways to V6_0_0_7 immediately to reduce the likelihood of compromise.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.