Select Page
Advisory IDSeverityRelease DateReported ByCVE ID
HSVD-2025-0013MediumApril 29, 2025External submissionN/A

Overview

An SSRF vulnerabilityHillstone LMS Arbitrary File Read Vulnerability. Due to the insufficient verification of user input by LMS, attackers with login permissions can read any files in the system through this vulnerability.

Affected Products & Fix Versions

PRODUCTAFFECTED VERSIONSFIX VERSION
LMSVersions before 3.6.15, versions before 4.3.23.6.15 and 4.3.2

Remediation & Mitigation

  • Repair by upgrading the version.

Contact & Reporting

For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.

To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.

Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.