Executive brief
MK-Auth is a management system used by Internet Service Providers (ISPs) to manage client access and permissions. A security flaw in the 'Fale Conosco' support component allows an authenticated user to upload malicious files to the server. If exploited, this allows an attacker to take full control of the system, potentially leading to service disruption or unauthorized access to sensitive ISP management data.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the Central/Suporte/Fale Conosco component of MK-Auth. Authenticated attackers can bypass PHP upload restrictions by appending a specific suffix (e.g., '.phpJunk123png') to their filename, which the server incorrectly validates but still executes as PHP. Although the system prepends a random string to uploaded filenames, the resulting file is stored in the '/mkfiles/' directory. An attacker can achieve Remote Code Execution (RCE) by brute-forcing the filename prefix and accessing the uploaded script via a web request.
Affected products
- MK-Auth MK-Auth 23.01K4.9 and possibly earlier
Timeline
- 2026-05-12: disclosed: Initial disclosure date
- 2026-05-12: advisory: NVD publication date