Executive brief
The Zettlab D6 Ultra is a network-attached storage (NAS) device marketed as an "AI NAS" that allows organizations to centralize file storage and run AI workloads. A path traversal vulnerability in its file listing API allows authenticated users to browse and download arbitrary files outside their designated personal folder, including sensitive system files like /etc/passwd. This undermines access controls and enables attackers to learn about system architecture in preparation for further exploitation.
Technical details
The vulnerability is an absolute path traversal flaw in the /zettos/main/file/v1/list API endpoint. The endpoint accepts a path parameter intended to be relative to a user's personal folder, but fails to validate or restrict the path, allowing an authenticated attacker to supply absolute paths (e.g., "/etc") to list and download files from anywhere on the filesystem. Authentication is required, but any valid user account can exploit the flaw. An attacker can enumerate system directories, retrieve sensitive files such as /etc/passwd and /etc/shadow, and gather reconnaissance on the system architecture. The vendor (Zettlab) has acknowledged the vulnerability and committed to fixing it in the 1.7.0 firmware release.
Affected products
- Zettlab D6 Ultra before 1.7.0
Timeline
- 2026-02-27: disclosed
- 2026-01-01: patched: Fix expected in version 1.7.0; original patch deadline Feb 13, 2026 was not met