| Advisory ID | Severity | Release Date | Reported By | CVE ID |
| HSVD-2026-0039 | Medium | September 4, 2026 | External submission | N/A |
Overview
In the restricted command-line interface (CLI) maintenance tool available after SSH login, the Hillstone HSA fails to adequately sanitize user-supplied input and directly concatenates it into system commands for execution. An authenticated attacker could craft special input to bypass the restricted CLI limitations and inject and execute arbitrary system commands, potentially gaining control of the device.
Affected Products & Fix Versions
| Product | Affected Version | Fixed Version |
|---|---|---|
| HSA | HSA2.22.7 and earlier versions | HSA2.22.9 |
Remediation & Mitigation
- Upgrade to a fixed version to remediate this vulnerability.
Contact & Reporting
For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.
To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.
Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.
Recent Comments