Hillstone Networks Operation and Maintenance Security Gateway Unrestricted File Upload Vulnerability

Vulnerability

A vulnerability allowing unrestricted file upload of dangerous types has been identified in Hillstone Networks Operation and Maintenance Security Gateway on Linux, specifically in version V5.5ST00001B113. This vulnerability allows attackers with administrative privileges to upload web shells to a web server, exploiting the lack of proper security checks and filtering mechanisms for user-uploaded files.

Impact

Exploitation of this vulnerability could lead to the upload of malicious files, such as web shells, which could be executed on the server.

Remediation

Users can apply the patch included in the 20251105 update to address this vulnerability.

Added: Feb 4, 2026, 4:17 AM
Updated: Feb 4, 2026, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.