| Advisory ID | Severity | Release Date | Reported By | CVE ID |
| HSVD-2026-0041 | Medium | August 11, 2026 | External submission | N/A |
Overview
After logging in via SSH to multiple Hillstone products, users enter a restricted command-line interface (CLI) operations tool. A backdoor command exists within this tool, allowing users to dynamically generate a password and obtain root privileges.
Affected Products & Fix Versions
| Product | Affected Version | Fixed Version |
|---|---|---|
| HSM | HSM < 5.6.8.1 | HSM 5.6.8.1 |
| DSGP | V2.0R2, V2.0R2P1, V2.0R3, V2.0R3P1 | V2.0R4 |
| iSource | R14 | R14P1 |
Remediation & Mitigation
- Upgrade to HSM 5.6.8.1, DSGP V2.0R3P2, and iSource R14P1 or later versions to fix this vulnerability.
Contact & Reporting
For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.
To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.
Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.
Recent Comments