Mbs Solutions develops a specialized line of Universal BACnet Router appliances, devices that bridge and manage building automation network traffic across multiple protocol domains. While the product portfolio is narrow, these routers occupy a foundational role in networked building control systems, and the vendor's disclosures are distributed across firmware versions and device models including the UBR-01 MK II, UBR-02, and UBR-LON platforms. The vulnerability surface does not show clear clustering around specific weakness classes, and the exposures reflect the integration and protocol-translation demands of building automation middleware. Defenders should monitor this vendor's advisories for environmental control and facility-management deployments, particularly where routers bridge legacy BACnet networks to modern IP infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mbs Solutions over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35075CRITICAL An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. | Jun 3, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-35085HIGH A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. | Jun 3, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-35084HIGH A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. | Jun 3, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-35083HIGH A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. | Jun 3, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-35082HIGH The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. | Jun 3, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-35080HIGH The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | Jun 3, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-35079HIGH The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | Jun 3, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-35078HIGH The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | Jun 3, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-35077HIGH The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | Jun 3, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-35076HIGH The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | Jun 3, 2026 | 8.1 | 35 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mbs Solutions.
Media articles that mention a CVE ID that affects a product developed by Mbs Solutions — matched by CVE ID, not by vendor name.