Executive brief
ATEN Unizon, a centralized management platform for AV and IT equipment, contains a security flaw in how it handles software updates. An attacker with administrative credentials can bypass security checks to upload a malicious update package. If successful, the attacker can take full control of the server, potentially leading to data theft or complete service disruption.
Technical details
A remote code execution vulnerability exists in ATEN Unizon's 'updateWar' method within the 'doCryptoHugeFileToFile' function. The application fails to properly verify cryptographic signatures when processing update packages via the 'rest/system/information' endpoint. Specifically, the system utilizes a hard-coded secret for encryption/decryption, allowing an attacker with high-level (administrative) privileges to craft and encrypt a malicious WAR file. Upon processing this file, the application executes the payload in the context of the SYSTEM user. This vulnerability is addressed in firmware version V2.7.264.001.
Affected products
- ATEN Unizon 2.6.253.001
Timeline
- 2026-03-13: disclosed: Vulnerability reported to vendor
- 2026-04-15: patched: Fixed version V2.7.264.001 released
- 2026-06-24: advisory: Coordinated public release of advisory