Junglewise Threat Intelligence

CVE-2026-9775: ATEN Unizon directory traversal in uploadSSL

CVE-2026-9775 · Severity: medium · CVSS 5.5 · Published 2026-06-24

Technologies: ATEN Unizon. Vendors: ATEN.

Executive brief

ATEN Unizon, a centralized management platform for AV and IT devices, contains a security flaw in its SSL certificate upload process. An authenticated administrator can exploit this flaw to delete critical system files by manipulating file paths. This could lead to a complete service outage or permanent loss of configuration data, disrupting business operations.

Technical details

A directory traversal vulnerability exists within the uploadSSL method of ATEN Unizon, specifically at the /rest/system/ssl endpoint. The application fails to properly validate user-supplied pathnames during SSL certificate upload operations. An authenticated attacker with high privileges can provide a manipulated filename containing traversal sequences (e.g., ../) to target and delete files outside of the intended directory. This can result in a denial-of-service condition by removing critical system or application files. The vulnerability is addressed in firmware version 2.7.264.001.

Affected products

  • ATEN Unizon 2.7.262.002 and earlier

Timeline

  • 2026-03-13: disclosed: Vulnerability reported to vendor
  • 2026-04-15: patched: Fixed version FW V2.7.264.001 released
  • 2026-06-24: advisory: Coordinated public release of advisory

References

Related threats