Description
Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.
Published: 2026-09-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure of Sensitive System Files
Action: Apply Fix
AI Analysis

Impact

The vulnerability in Zettlab D6 Ultra allows an attacker to use path traversal characters in a Docker compose file to mount host files such as /etc/passwd and /etc/shadow into a:/h_etc:rw, the attacker can read the host system’s credential files, exposing user account names and password hashes. This constitutes sensitive information disclosure that could aid credential cracking or privilege escalation if the hashed passwords are weak.

Affected Systems

This issue affects the Zettlab D6 Ultra device running firmware versions prior to 1.7.0. No other models or services from Zettlab are listed as vulnerable. The flaw exists in the compose file handler responsible for processing volume mounts.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The attack vector is inferred to be local or dependent on the ability to provide or modify a compose file; if the device accepts externally supplied compose definitions, a remote attacker could create a maliciouswd and /etc/shadow. The exploit requires no additional privileges beyond the ability to run or submit the Compose configuration, so the risk escalates where untrusted users can influence container definitions.

Generated by OpenCVE AI on September 15, 2026 at 17:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Zettlab D6 Ultra firmware to version 1.7.0 or later, which removes the ability to resolve '..' in volume paths.
  • If firmware update is delayed, configure the device to sanitize or reject compose files that contain '..' glob patterns in volume mounts.
  • Audit running containers for unexpected mounts to /etc/passwd those mounts to prevent unauthorized access.

Generated by OpenCVE AI on September 15, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Zettlab
Zettlab d6 Ultra
Vendors & Products Zettlab
Zettlab d6 Ultra

Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Mount of Sensitive Host Files via Docker Compose Volume Paths

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Mounting of Host System Password Files in Zettlab D6 Ultra
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allowing Mounting of Host System Password Files in Zettlab D6 Ultra

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-24
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Sun, 13 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.
References

Subscriptions

Zettlab D6 Ultra
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:54:29.840Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70819

cve-icon Vulnrichment

Updated: 2026-09-14T15:54:22.832Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:52.850

Modified: 2026-09-22T20:00:03.713

Link: CVE-2025-70819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:44Z

Weaknesses
  • CWE-24

    Path Traversal: '../filedir'