CVE-2026-78212

7.5

4MOSAn Security Technology Co · 4MOSAn Management Center

The 4MOSAn Management Center is affected by a relative path traversal vulnerability, which may allow an unauthenticated attacker to access unauthorized files on the system.

Executive summary

A relative path traversal vulnerability in 4MOSAn Management Center versions prior to 20260621 allows unauthorized file access and poses a significant security risk.

Vulnerability

The product is susceptible to CWE-23 (Relative Path Traversal), which allows an unauthenticated, remote attacker to manipulate file paths and access sensitive information on the server.

Business impact

Path traversal vulnerabilities can lead to the exposure of sensitive configuration files, source code, or internal system data. Given the CVSS score of 7.5, this vulnerability is considered high risk because it allows an unauthenticated attacker to bypass security controls and read arbitrary files from the filesystem, directly impacting the confidentiality of the affected infrastructure.

Remediation

Immediate Action: Upgrade to version 20260621 or later and perform the necessary security upgrades for the FreeBSD-GCB Management Center.

Proactive Monitoring: Review server access logs for patterns indicative of directory traversal attempts, such as sequences containing dot-dot-slash.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block path traversal patterns in incoming HTTP requests.

Exploitation status

Public Exploit Available: No (no confirmed public exploit identified).

Analyst recommendation

The vulnerability is urgent due to the lack of authentication required for exploitation. Administrators must apply the vendor-provided patch immediately to prevent unauthorized access to the underlying system files.

More 4MOSAn Security Technology Co CVEs