Hillstone Networks Operation and Maintenance Security Gateway Unrestricted File Upload Vulnerability
Vulnerability
A vulnerability allowing unrestricted file upload of dangerous types has been identified in Hillstone Networks Operation and Maintenance Security Gateway on Linux, specifically in version V5.5ST00001B113. This vulnerability allows attackers with administrative privileges to upload web shells to a web server, exploiting the lack of proper security checks and filtering mechanisms for user-uploaded files.
Impact
Exploitation of this vulnerability could lead to the upload of malicious files, such as web shells, which could be executed on the server.
Remediation
Users can apply the patch included in the 20251105 update to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
