Junglewise Threat Intelligence

CVE-2026-9778: ATEN Unizon directory traversal remote code execution in ImportDeviceList

CVE-2026-9778 · Severity: high · CVSS 7.2 · Published 2026-06-24

Technologies: ATEN Unizon. Vendors: ATEN.

Executive brief

ATEN Unizon, a centralized management platform for AV and IT devices, contains a security flaw in its device list import feature. An authenticated attacker with administrative privileges can exploit this flaw to bypass folder restrictions and run unauthorized commands on the underlying server. This could lead to a complete takeover of the management system and the data it controls, potentially disrupting operations across the connected device network.

Technical details

A directory traversal vulnerability exists in the ATEN Unizon `/rest/devices/csv` endpoint within the `ImportDeviceList` method. The flaw is caused by insufficient validation of user-supplied file paths during CSV file upload operations. An authenticated attacker with high privileges (PR:H) can provide a manipulated path to escape the intended directory and write or interact with files in restricted locations. Successful exploitation allows for remote code execution in the security context of the SYSTEM account. ATEN has addressed this in firmware version 2.7.264.001.

Affected products

  • ATEN Unizon 2.7.262.002 and earlier versions prior to 2.7.264.001

Timeline

  • 2026-03-13: disclosed: Vulnerability reported to vendor via ZDI
  • 2026-04-15: patched: Firmware version 2.7.264.001 released
  • 2026-06-24: advisory: Coordinated public release of advisory

References

Related threats