Executive brief
ATEN Unizon, a centralized management platform for AV and IT devices, contains a security flaw that allows an authenticated administrator to delete files on the server. By exploiting this vulnerability, an attacker can remove critical system files, potentially leading to a complete service outage or system instability. This could disrupt business operations and require significant recovery efforts to restore the management platform.
Technical details
A directory traversal vulnerability exists within the `updateLicense` method of the `LicenseController` in ATEN Unizon. The flaw is located in the `/rest/system/license` endpoint handler, where the application fails to properly validate user-supplied filenames during license file operations. An authenticated attacker with administrative privileges can provide a manipulated path to traverse the file system and delete arbitrary files with NT\SYSTEM privileges. This can be used to cause a denial-of-service (DoS) condition by deleting critical application or system files. The issue is addressed in firmware version V2.7.264.001.
Affected products
- ATEN Unizon 2.7.262.002 and earlier
Timeline
- 2026-03-13: disclosed: Vulnerability reported to vendor
- 2026-04-15: patched: Fixed version FW V2.7.264.001 released
- 2026-06-24: advisory: Coordinated public release of advisory