PT-2026-85681 · Undefined · Undefined

CVE-2026-75166

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6 00 05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.

Exploit

Correção

Incorrect Default Permissions

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-75166

Produtos afetados

Undefined