| Advisory ID | Severity | Release Date | Reported By | CVE ID |
| HSVD-2025-0015 | High | April 29, 2025 | External submission | N/A |
Overview
Hillstone HSA Multiple Command Injection Vulnerabilities. These vulnerabilities are caused by the fact that the system does not effectively filter the user’s input and directly splices the system command execution, resulting in remote code execution vulnerabilities. Attackers with administrator rights can execute arbitrary system commands by constructing malicious requests.
Affected Products & Fix Versions
| PRODUCT | AFFECTED VERSIONS | FIX VERSION |
|---|---|---|
| HSA | Versions before 2.20.4 | 2.20.4 |
Remediation & Mitigation
- Repair by upgrading the version.
Contact & Reporting
For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.
To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.
Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.
Recent Comments