| Advisory ID | Severity | Release Date | Reported By | CVE ID |
| HSVD-2026-0036 | High | September 4, 2026 | External submission | N/A |
Overview
The OpenAPI file import function of Hillstone WAF is affected by an authenticated root code execution vulnerability. This is a backend vulnerability that requires authenticated administrator privileges. After obtaining an authenticated web session, an attacker can upload a maliciously crafted file through this import function. Because the backend uses an insecure deserialization method when parsing the untrusted content, arbitrary system commands can be executed as root before business validation is performed.
Affected Products & Fix Versions
| Product | Affected Version | Fixed Version |
|---|---|---|
| WAF | WAF2.7 and later | WAF3.6.15, WAF4.1.2 |
Remediation & Mitigation
- Upgrade to a fixed version to remediate this vulnerability.
Contact & Reporting
For technical support and detailed remediation guidance, contact Hillstone Networks support at +1-800-930-6707.
To report security issues in Hillstone products, email PSIRT@hillstonenet.com. Hillstone follows responsible disclosure principles and applicable regulations when handling product security incidents.
Legal notice — Without written authorization from Hillstone Networks, no organization or individual may modify, excerpt, or disseminate the content of this advisory for commercial purposes.
Recent Comments