Executive brief
The Intrado 911 Emergency Gateway, which manages emergency call routing and location services, contains a critical security flaw. An unauthorized person can remotely access, modify, or delete sensitive system files without needing a password. This could lead to a complete system takeover, disruption of emergency services, or the exposure of confidential operational data.
Technical details
A path traversal vulnerability (CWE-35) exists in the 'download_debuglog_file.php' endpoint of the Intrado 911 Emergency Gateway. The vulnerability stems from insufficient validation of the 'name' parameter used during debug log downloads. A remote, unauthenticated attacker can use directory traversal sequences (e.g., ../) to escape the intended directory and read, modify, or delete arbitrary files on the system. This can lead to full system compromise or unauthorized access to the management interface. Intrado released a software update on March 2, 2026, to address the issue.
Affected products
- Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, 7.x
Timeline
- 2026-03-02: patched: Intrado released a software update and began coordinating with customers.
- 2026-04-23: disclosed: Initial publication of ICSA-26-113-06.
- 2026-05-07: advisory: Last revision of the CISA advisory.