Remote File Deletion Vulnerability in UGW Software by Vendor
CVE-2026-35080
7.2HIGH
What is CVE-2026-35080?
A remote file deletion vulnerability has been identified in UGW Software that stems from inadequate validation of user-controlled input in the ugw-restoreinfo method. This flaw permits a remote attacker with user privileges to maliciously delete arbitrary files on the local system, posing significant risks to data integrity and availability. Organizations using this software should prioritize applying security measures to mitigate the risks posed by this vulnerability.
Affected Version(s)
Double-A Profibus V1_0_0_0
Double-A x-link V1_0_0_0
Double-X CAN V1_0_0_0
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
