CVE-2026-75160

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

Published 2026-09-04. Last modified 2026-09-08.