Junglewise Threat Intelligence

CVE-2026-13547: Hanwang e-Face General Management Platform unrestricted file upload

CVE-2026-13547 · Severity: high · CVSS 7.3 · Published 2026-06-29

Executive brief

Hanwang e-Face General Management Platform, a facial recognition management system, contains a security flaw that allows unauthorized users to upload files to the server. An attacker could exploit this to place malicious files on the system, potentially leading to a full compromise of the platform and its data. This vulnerability can be exploited remotely without requiring any user interaction or login credentials.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in Hanwang e-Face General Management Platform version 6.3.5.4. The flaw is located in the '/manage/resourceUpload/upload.do' endpoint due to improper validation of the 'File' parameter. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files, potentially including web shells or other malicious scripts. Successful exploitation could lead to remote code execution (RCE) on the underlying server. The exploit has been publicly disclosed.

Affected products

  • Hanwang e-Face General Management Platform 6.3.5.4

Timeline

  • 2026-06-29: advisory: NVD publication date
  • 2026-06-29: disclosed: Public disclosure of the exploit

References