Security Advisories
Hillstone Network Security Advisories
Hillstone Networks Product Security Incident Response Team (PSIRT) is responsible for receiving, assessing, and publicly disclosing security vulnerabilities affecting Hillstone products and services. As the company’s official vulnerability disclosure channel, Hillstone Networks PSIRT is dedicated to protecting customers and partners through responsible disclosure practices and by ensuring compliance with applicable laws and regulations in the management and remediation of product security issues.
Hillstone ADC gslbd_dns_zone Creation Chain named-checkzone Post-Authentication Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0025HighSeptember 4, 2026External submissionN/A Overview The GSLB DNS zone creation function of the Hillstone ADC product contains a post-authentication command execution vulnerability. An authenticated...
Hillstone WAF wafd_openapi_file YAML Deserialization Authenticated Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0036HighSeptember 4, 2026External submissionN/A Overview The OpenAPI file import function of Hillstone WAF is affected by an authenticated root code execution vulnerability. This is a backend vulnerability that...
Hillstone ADC troubleshooting tcpdump SSL keylog Post-Authentication Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0023HighSeptember 4, 2026External submissionN/A Overview A command injection vulnerability exists in the backend diagnostic packet capture (tcpdump) interface of the Hillstone ADC. When an authenticated...
Hillstone ADC gslbd_dns exec_refresh Post-Authentication Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0024HighSeptember 4, 2026External submissionN/A Overview The GSLB DNS refresh interface of Hillstone ADC contains a post-authentication command execution vulnerability. An authenticated administrator can...
Hillstone HSA Local Command Injection Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0039MediumSeptember 4, 2026External submissionN/A Overview In the restricted command-line interface (CLI) maintenance tool available after SSH login, the Hillstone HSA fails to adequately sanitize user-supplied...
Hillstone ADC diagnostic_file_export Arbitrary File Download Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0028MediumSeptember 4, 2026External submissionN/A Overview Hillstone ADC contains an arbitrary file download vulnerability in diagnostic_file_export. It is a backend vulnerability requiring authenticated...
Hillstone Multiple Products Local Command Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0041MediumAugust 11, 2026External submissionN/A Overview After logging in via SSH to multiple Hillstone products, users enter a restricted command-line interface (CLI) operations tool. A backdoor command exists...
Hillstone HSA Arbitrary File Upload Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0046HighAugust 11, 2026External submissionCNNVD-2026-79982062 Overview The resumable file upload interface in Hillstone HSA does not validate file names for path traversal. An attacker can upload a malicious...
Hillstone HSA Web Command Injection Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0040HighAugust 11, 2026External submissionN/A Overview After user authentication, the Web management interface of Hillstone HSA lacks effective filtering of user-controllable request parameters and directly...
Hillstone WAF wafd_error_page Authenticated Root Code Execution Vulnerability
Advisory IDSeverityRelease DateReported ByCVE IDHSVD-2026-0034HighJuly 27, 2026External submissionN/A Overview Hillstone WAF contains an authenticated arbitrary command execution vulnerability in the custom error page feature. The vulnerability exists because the...
For the 4th year in a row, Hillstone Networks has been recognized in Gartner Peer Insights Customers’ Choice for Network Firewalls.
The Customers’ Choice is a rating of vendors in a given market — for Hillstone, it’s Network Firewalls — that take into account both the number of reviews and the overall user rating. Based on feedback and ratings from our end users who have purchased, implemented and are happily using our products and services, Hillstone’s overall rating came to 4.9.