Select Page
Advisory IDSeverityRelease DateReported ByCVE ID
HSVD-2026-0046HighAugust 11, 2026External submissionCNNVD-2026-79982062

Overview

The resumable file upload interface in Hillstone HSA does not validate file names for path traversal. An attacker can upload a malicious script file to the web root directory via path traversal. This interface does not require authentication, which can lead to remote code execution.

Affected Products & Fix Versions

ProductAffected VersionFixed Version
HSAHSA 2.22.7 and earlier versionsHSA 2.22.8

Remediation & Mitigation

  • Upgrade to HSA 2.22.8 or later versions to fix this vulnerability.

Contact & Reporting

For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.

To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.

Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.