| Advisory ID | Severity | Release Date | Reported By | CVE ID |
| HSVD-2026-0034 | High | July 27, 2026 | External submission | N/A |
Overview
Hillstone WAF contains an authenticated arbitrary command execution vulnerability in the custom error page feature. The vulnerability exists because the backend concatenates user-controlled content into a shell command for execution without proper input validation, allowing an authenticated administrator to execute arbitrary system commands with Root privileges.
Affected Products & Fix Versions
| Product | Affected Version | Fixed Version |
|---|---|---|
| WAF | WAF2.2 and later, prior to WAF4.1.2 | WAF4.1.2 |
Remediation & Mitigation
- Repair by upgrading the version.
Contact & Reporting
For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.
To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.
Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.
Recent Comments