Executive brief
ATEN Unizon, a centralized management software for AV and IT equipment, contains a security flaw in its database restoration feature. An authenticated attacker with administrative privileges can exploit this to run unauthorized commands on the underlying server. This could lead to a complete takeover of the management system and the infrastructure it controls.
Technical details
A directory traversal vulnerability exists within the restoreDB method of ATEN Unizon, specifically at the /rest/system/database/restore endpoint. The application fails to properly validate user-supplied file paths during database restoration operations. By providing a specially crafted path, an authenticated attacker can perform arbitrary file operations. This can be leveraged to achieve remote code execution in the security context of the SYSTEM account. The vulnerability was addressed in firmware version V2.7.264.001.
Affected products
- ATEN Unizon 2.7.262.002
Timeline
- 2026-03-13: disclosed: Vulnerability reported to vendor
- 2026-04-15: patched: Firmware V2.7.264.001 released
- 2026-06-24: advisory: Coordinated public release of advisory