File Deletion Vulnerability in UGW Logging Method Affecting Vendor Software
CVE-2026-35078
7.2HIGH
What is CVE-2026-35078?
The UGW logging method contains a vulnerability that allows a remote attacker, with user privileges, to exploit insufficient validation of user-controlled input. This flaw enables unauthorized deletion of arbitrary local files, potentially compromising the integrity and confidentiality of the affected system. Proper input validation measures are critical to mitigating this risk.
Affected Version(s)
Double-A Profibus V1_0_0_0
Double-A x-link V1_0_0_0
Double-X CAN V1_0_0_0
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
