Select Page
Advisory IDSeverityRelease DateReported ByCVE ID
HSVD-2026-0028MediumSeptember 4, 2026External submissionN/A

Overview

Hillstone ADC contains an arbitrary file download vulnerability in diagnostic_file_export. It is a backend vulnerability requiring authenticated administrator privileges. The diagnostic file export interface is affected by a path traversal flaw: an attacker can use the controllable file_name parameter to specify an arbitrary sensitive file path, which the device will package as a tar file and allow to be downloaded.

Affected Products & Fix Versions

ProductAffected VersionFixed Version
ADCAX2.5 and laterAX5.0.1

Remediation & Mitigation

  • Upgrade to a fixed version to remediate this vulnerability.

Contact & Reporting

For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.

To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.

Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.