Hydrosystem Control System Missing Authorization Vulnerability Allowing Unauthorized File Access and Execution

Vulnerability

A vulnerability exists in Hydrosystem Control System prior to version 9.8.5, where the application fails to enforce proper authorization for certain directories. This oversight enables unauthorized users to read and execute files within these directories. Notably, attackers can directly run PHP scripts on the connected database, potentially leading to severe consequences.

Impact

Exploitation of this vulnerability allows unauthorized access to sensitive files and the execution of scripts that can manipulate the connected database.

Remediation

Users can upgrade to Hydrosystem Control System version 9.8.5 or later to address this vulnerability.

Added: Apr 9, 2026, 10:27 AM
Updated: Apr 9, 2026, 10:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
5.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.