Executive brief
Ziostation2, a medical imaging and diagnostic software solution, contains a security flaw that allows unauthorized access to system files. An attacker can remotely access the server without a password to steal sensitive configuration files or operating system data. This could lead to the exposure of private system information and potentially assist in further attacks on the medical facility's infrastructure.
Technical details
A path traversal vulnerability (CWE-22) exists in Ziosoft Ziostation2 versions up to and including v2.9.8.7. The flaw allows a remote, unauthenticated attacker to bypass directory restrictions by using specially crafted input, such as dot-dot-slash (../) sequences, to access files outside of the intended web or application root. Successful exploitation enables the attacker to read sensitive files on the underlying operating system. The vendor has released updates to address this issue, and users are advised to upgrade to the latest version.
Affected products
- Ziosoft, Inc. Ziostation2 v2.9.8.7 and earlier
Timeline
- 2026-04-22: disclosed: Initial disclosure by JPCERT/CC and JVN
- 2026-04-22: advisory
- 2026-04-23: other: NVD publication date