Sceawere
Vulnerability Detail
CVE-2026-101071UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Acrel Unet Unrestricted File Upload
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 3h ago
- Vendor
- Acrel Electric
- Product
- Unet Web Service
- Attack Type
- Unrestricted Upload
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-28T14:17:13.770Z",
"pubdate": "2026-09-28T14:17:13.770Z",
"executiveSummary": "A critical security vulnerability has been identified in the Acrel Electric Unet Web Service, specifically within the /exchange/attachment/upload endpoint.\nThe vulnerability is classified as an unrestricted file upload flaw, which allows unauthenticated remote attackers to upload arbitrary files to the server.\nThis flaw poses a severe risk to system integrity and confidentiality, as it facilitates the execution of malicious code, such as web shells, leading to potential full system compromise.\nThe affected product is Acrel Electric Unet Web Service up to version 20260814. The vendor has been notified but has remained unresponsive.\nThe vulnerability is currently publicly disclosed, increasing the risk of active exploitation by threat actors.\nSuccessful exploitation requires network connectivity to the target service but does not appear to require authentication or advanced privileges.",
"technicalDetails": "The vulnerability resides within the /exchange/attachment/upload file handling component of the Acrel Electric Unet Web Service. The root cause is the lack of proper input validation, file type filtering, and sanitization mechanisms on the server-side during the file reception process.\nThe application fails to restrict the 'File' argument, which serves as the payload carrier for the upload operation. An attacker can transmit crafted HTTP requests to the target endpoint containing malicious file content, such as server-side scripts (e.g., .php, .jsp, .aspx, or .sh), despite the intended function of the endpoint.\nThe attack flow follows a direct exploitation pattern: First, the attacker identifies the /exchange/attachment/upload path, which is exposed over the network. Second, the attacker constructs an HTTP POST request including the 'File' parameter with a malicious payload. Third, the server processes this request and saves the attacker-supplied content to a persistent directory on the host filesystem without verifying the MIME type, file extension, or file content signature.\nSince the application does not enforce strict extension whitelisting or rename the uploaded files to randomized or non-executable formats, the attacker can influence the destination path or rely on default directory configurations to achieve remote code execution (RCE).\nOnce the malicious file is uploaded, the attacker can navigate to the known path of the uploaded artifact and trigger its execution via a standard HTTP GET request. This allows for the execution of arbitrary commands with the privileges of the web service process.\nThe impact of this vulnerability is significant, enabling complete system compromise, data exfiltration, and the establishment of persistent backdoors within the network environment. The exploit is remote and does not mandate pre-existing authentication, making it a high-priority risk for any internet-facing deployment of the affected Acrel Electric Unet service versions up to 20260814."
}