Select Page
Advisory IDSeverityRelease DateReported ByCVE ID
HSVD-2026-0006HighJune 18, 2026External submissionN/A

Overview

Hillstone HSM5 contains a remote command execution vulnerability. The vulnerability exists because the system does not properly validate input from authenticated users and directly concatenates it into system commands, resulting in remote code execution.

Affected Products & Fix Versions

PRODUCTAFFECTED VERSIONSFIX VERSION
HSM5.XHSM5.6.13 and earlier versionsHSM5.6.13.1

Remediation & Mitigation

  • Repair by upgrading the version.

Contact & Reporting

For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.

To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.

Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.