Security Advisories
Hillstone Network Security Advisories
Hillstone Networks Product Security Incident Response Team (PSIRT) is responsible for receiving, assessing, and publicly disclosing security vulnerabilities affecting Hillstone products and services. As the company’s official vulnerability disclosure channel, Hillstone Networks PSIRT is dedicated to protecting customers and partners through responsible disclosure practices and by ensuring compliance with applicable laws and regulations in the management and remediation of product security issues.
Hillstone Multiple Products Local Command Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0041MediumAugust 11, 2026External submissionN/A Overview After logging in via SSH to multiple Hillstone products, users enter a restricted command-line interface (CLI) operations tool. A backdoor command exists...
Hillstone HSA Web Command Injection Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0040HighAugust 11, 2026External submissionN/A Overview After user authentication, the Web management interface of Hillstone HSA lacks effective filtering of user-controllable request parameters and directly...
Hillstone HSA Arbitrary File Upload Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0046HighAugust 11, 2026External submissionCNNVD-2026-79982062 Overview The resumable file upload interface in Hillstone HSA does not validate file names for path traversal. An attacker can upload a malicious...
Hillstone WAF wafd_error_page Authenticated Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0034HighJuly 27, 2026External submissionN/A Overview Hillstone WAF contains an authenticated arbitrary command execution vulnerability in the custom error page feature. The vulnerability exists because the...
Hillstone WAF wafd_vul_report Authenticated Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0035HighJuly 27, 2026External submissionN/A Overview Hillstone WAF contains an authenticated arbitrary command execution vulnerability in the vulnerability report processing feature. The vulnerability exists...
Hillstone WAF wafd_antidefacement_confirm Authenticated Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0033HighJuly 27, 2026External submissionN/A Overview Hillstone WAF contains an authenticated arbitrary command execution vulnerability in the web anti-defacement confirmation feature. The vulnerability exists...
Hillstone HSM Multiple Unauthenticated Arbitrary Command Execution Vulnerabilities
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0014HighJune 18, 2026External submissionN/A Overview Hillstone HSM contains multiple unauthenticated arbitrary command execution vulnerabilities. These vulnerabilities exist because the system does not properly...
Hillstone HSM Arbitrary File Write Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0013HighJune 18, 2026External submissionN/A Overview Hillstone HSM contains an arbitrary file write vulnerability. The vulnerability exists because the system does not strictly validate or restrict...
Hillstone HSM Arbitrary File Deletion Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0012MediumJune 18, 2026External submissionN/A Overview Hillstone HSM contains an arbitrary file deletion vulnerability. The vulnerability exists because the system does not properly validate user-supplied file...
Hillstone HSM Multiple Arbitrary Command Execution Vulnerabilities
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0011HighJune 18, 2026External submissionN/A Overview Hillstone HSM contains multiple arbitrary command execution vulnerabilities. These vulnerabilities exist because the system does not properly validate input...
For the 4th year in a row, Hillstone Networks has been recognized in Gartner Peer Insights Customers’ Choice for Network Firewalls.
The Customers’ Choice is a rating of vendors in a given market — for Hillstone, it’s Network Firewalls — that take into account both the number of reviews and the overall user rating. Based on feedback and ratings from our end users who have purchased, implemented and are happily using our products and services, Hillstone’s overall rating came to 4.9.