Select Page
Advisory IDSeverityRelease DateReported ByCVE ID
HSVD-2026-0036HighSeptember 4, 2026External submissionN/A

Overview

The OpenAPI file import function of Hillstone WAF is affected by an authenticated root code execution vulnerability. This is a backend vulnerability that requires authenticated administrator privileges. After obtaining an authenticated web session, an attacker can upload a maliciously crafted file through this import function. Because the backend uses an insecure deserialization method when parsing the untrusted content, arbitrary system commands can be executed as root before business validation is performed.

Affected Products & Fix Versions

ProductAffected VersionFixed Version
WAFWAF2.7 and laterWAF3.6.15, WAF4.1.2

Remediation & Mitigation

  • Upgrade to a fixed version to remediate this vulnerability.

Contact & Reporting

For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.

To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.

Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.