Executive brief
TeamT5 ThreatSonar Anti-Ransomware, a security solution designed to protect organizations from ransomware attacks, contains a vulnerability that allows for unauthorized file deletion. An authenticated attacker with web access can exploit this flaw to delete critical system files. This could lead to significant service disruptions, loss of security logs, or the disabling of the anti-ransomware protection itself.
Technical details
An arbitrary file deletion vulnerability exists in TeamT5 ThreatSonar Anti-Ransomware due to improper limitation of a pathname to a restricted directory (CWE-22/CWE-23). An authenticated remote attacker with web access can provide specially crafted input containing path traversal sequences (e.g., ../) to target and delete files outside of the intended directory. Successful exploitation allows the attacker to delete arbitrary files on the underlying system, potentially leading to a denial-of-service condition or the removal of critical security configurations. The vulnerability is addressed in version 4.0.0.
Affected products
- TeamT5 ThreatSonar Anti-Ransomware versions up to (excluding) 4.0.0
Timeline
- 2026-04-20: disclosed
- 2026-04-20: advisory