| Advisory ID | Severity | Release Date | Reported By | CVE ID |
| HSVD-2026-0023 | High | September 4, 2026 | External submission | N/A |
Overview
A command injection vulnerability exists in the backend diagnostic packet capture (tcpdump) interface of the Hillstone ADC. When an authenticated administrator initiates a packet capture task with SSL enabled, malicious content submitted via the password parameter is not safely escaped for shell usage and is concatenated into a shell command for execution. This allows arbitrary commands to be executed with root privileges, resulting in complete compromise of the device.
Affected Products & Fix Versions
| Product | Affected Version | Fixed Version |
|---|---|---|
| ADC | AX3.2 through AX5.0 | AX5.0.1 |
Remediation & Mitigation
- Upgrade to a fixed version to remediate this vulnerability.
Contact & Reporting
For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.
To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.
Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.
Recent Comments