Executive brief
Acrel Electrical EEMS, a cloud platform used for managing power substation operations, contains a security flaw that allows unauthorized access to files. By sending a specially crafted web request, an attacker can bypass directory restrictions to view or manipulate sensitive system files. This could lead to the exposure of operational data or disruption of power management services.
Technical details
A path traversal vulnerability (CWE-22) exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform version 1.3.0. The flaw is located in the handling of the 'path' argument within the '/SubstationWEBV2/app/..;/main/upfile' endpoint. A remote, unauthenticated attacker can manipulate this parameter to navigate the file system and access sensitive files. The exploit has been publicly disclosed, and as of the advisory date, the vendor has not responded to disclosure attempts or provided a patch.
Affected products
- Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0
Timeline
- 2026-05-26: advisory: NVD publication date
- 2026-05-26: disclosed: Public disclosure of the exploit