Junglewise Threat Intelligence

CVE-2026-6074: Intrado 911 Emergency Gateway path traversal in download_debuglog_file.php

CVE-2026-6074 · Severity: critical · CVSS 9.8 · Published 2026-04-23

Executive brief

The Intrado 911 Emergency Gateway, which manages emergency call routing and location services, contains a critical security flaw. An unauthorized person can remotely access, modify, or delete sensitive system files without needing a password. This could lead to a complete system takeover, disruption of emergency services, or the exposure of confidential operational data.

Technical details

A path traversal vulnerability (CWE-35) exists in the 'download_debuglog_file.php' endpoint of the Intrado 911 Emergency Gateway. The vulnerability stems from insufficient validation of the 'name' parameter used during debug log downloads. A remote, unauthenticated attacker can use directory traversal sequences (e.g., ../) to escape the intended directory and read, modify, or delete arbitrary files on the system. This can lead to full system compromise or unauthorized access to the management interface. Intrado released a software update on March 2, 2026, to address the issue.

Affected products

  • Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, 7.x

Timeline

  • 2026-03-02: patched: Intrado released a software update and began coordinating with customers.
  • 2026-04-23: disclosed: Initial publication of ICSA-26-113-06.
  • 2026-05-07: advisory: Last revision of the CISA advisory.

References