Junglewise Threat Intelligence

CVE-2026-5601: Acrel Electrical Prepaid Cloud Platform information disclosure in Backup File Handler

CVE-2026-5601 · Severity: medium · CVSS 5.3 · Published 2026-04-05

Executive brief

Acrel Electrical Prepaid Cloud Platform, a system used for managing utility payments and electrical data, contains a security flaw where sensitive backup files are publicly accessible. An attacker can download these files to obtain private information such as database credentials and internal server addresses. This could lead to unauthorized access to customer payment records, data theft, or further disruption of the platform's operations.

Technical details

The vulnerability is a classic information disclosure (CWE-200) resulting from improper access control (CWE-284) on the Backup File Handler component. Specifically, a compressed backup file named 'bin.rar' is stored within the web root directory and is accessible via a direct unauthenticated HTTP request. This archive contains the application's source code and configuration files, such as 'JuCheap.Data.dll.config', which store sensitive data including intranet IP addresses and cleartext database credentials. An attacker can exploit this to gain a foothold in the backend database or perform lateral movement within the internal network. While the vendor was notified, no official patch has been confirmed; remediation involves removing the backup files from the web directory and rotating compromised credentials.

Affected products

  • Acrel Electrical Prepaid Cloud Platform 1.0

Timeline

  • 2026-04-05: disclosed: Vulnerability disclosed via VulDB and GitHub report.
  • 2026-04-05: advisory
  • 2026-04-05: other: Vendor was contacted but did not respond.

References