Suprema BioStar 2 Backup File Exposure Vulnerability

Vulnerability

A vulnerability exists in Suprema BioStar 2 versions 2.9.3 through 2.9.11, due to incorrect permission settings on a critical resource. This flaw allows backup files to be publicly accessible when the administrator specifies their path within the NGINX webroot. As a result, an attacker with network access can directly download backup ZIP files without authentication, exposing highly sensitive information that could lead to server impersonation, unauthorized database access, and lateral movement within the network.

Impact

Exploitation of this vulnerability allows for unauthorized access to backup files containing sensitive information, which could be used for server impersonation, unauthorized database access, and lateral movement within the network.

Remediation

Users are advised to update to the latest available version of Suprema BioStar 2.

Added: May 29, 2026, 1:19 PM
Updated: May 29, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
7.0
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.