Sceawere

Vulnerability Detail

CVE-2026-101071UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Acrel Unet Unrestricted File Upload

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
Acrel Electric
Product
Unet Web Service
Attack Type
Unrestricted Upload
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-28T14:17:13.770Z",
  "pubdate": "2026-09-28T14:17:13.770Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Acrel Electric Unet Web Service, specifically within the /exchange/attachment/upload endpoint.\nThe vulnerability is classified as an unrestricted file upload flaw, which allows unauthenticated remote attackers to upload arbitrary files to the server.\nThis flaw poses a severe risk to system integrity and confidentiality, as it facilitates the execution of malicious code, such as web shells, leading to potential full system compromise.\nThe affected product is Acrel Electric Unet Web Service up to version 20260814. The vendor has been notified but has remained unresponsive.\nThe vulnerability is currently publicly disclosed, increasing the risk of active exploitation by threat actors.\nSuccessful exploitation requires network connectivity to the target service but does not appear to require authentication or advanced privileges.",
  "technicalDetails": "The vulnerability resides within the /exchange/attachment/upload file handling component of the Acrel Electric Unet Web Service. The root cause is the lack of proper input validation, file type filtering, and sanitization mechanisms on the server-side during the file reception process.\nThe application fails to restrict the 'File' argument, which serves as the payload carrier for the upload operation. An attacker can transmit crafted HTTP requests to the target endpoint containing malicious file content, such as server-side scripts (e.g., .php, .jsp, .aspx, or .sh), despite the intended function of the endpoint.\nThe attack flow follows a direct exploitation pattern: First, the attacker identifies the /exchange/attachment/upload path, which is exposed over the network. Second, the attacker constructs an HTTP POST request including the 'File' parameter with a malicious payload. Third, the server processes this request and saves the attacker-supplied content to a persistent directory on the host filesystem without verifying the MIME type, file extension, or file content signature.\nSince the application does not enforce strict extension whitelisting or rename the uploaded files to randomized or non-executable formats, the attacker can influence the destination path or rely on default directory configurations to achieve remote code execution (RCE).\nOnce the malicious file is uploaded, the attacker can navigate to the known path of the uploaded artifact and trigger its execution via a standard HTTP GET request. This allows for the execution of arbitrary commands with the privileges of the web service process.\nThe impact of this vulnerability is significant, enabling complete system compromise, data exfiltration, and the establishment of persistent backdoors within the network environment. The exploit is remote and does not mandate pre-existing authentication, making it a high-priority risk for any internet-facing deployment of the affected Acrel Electric Unet service versions up to 20260814."
}
CVE-2026-101071: Acrel Unet Unrestricted File Upload (MEDIUM Severity, CVSS: 6.3) | Sceawere