Executive brief
ArkSigner AcBakImzala, a software solution used for digital signature and backup operations, contains a critical security flaw. An attacker can exploit this vulnerability to remotely access sensitive files or execute unauthorized code on the system. This could lead to a total compromise of the server, resulting in data theft or service disruption.
Technical details
The vulnerability is classified as a Local File Inclusion (LFI) resulting from CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program) and CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). The flaw exists in ArkSigner AcBakImzala versions prior to 5.1.4. An unauthenticated attacker can exploit this over the network by providing malicious input to PHP file inclusion functions. This allows the attacker to read sensitive local files or, if combined with other techniques like log poisoning, achieve remote code execution (RCE). The issue has been addressed in version 5.1.4.
Affected products
- ArkSigner Software and Hardware Inc. AcBakImzala before v5.1.4
Timeline
- 2025-10-23: advisory: Initial publication by TR-CERT/USOM