Impact
The Unet Web Service processes file uploads from the /exchange/attachment/upload endpoint without validating the file type. This lack of validation allows an attacker to upload arbitrary files, which could be used to compromise confidentiality, integrity, and availability of the service. The weakness is identified by the Common Weakness Enumeration identifiers for Improper Access Control (CWE-284) and Untrusted File Upload (CWE-434).
Affected Systems
Acrel Electric Unet Web Service, versions up to 2026-08-14, are affected. The vulnerability exists in the Upload Endpoint for the /exchange/attachment/upload route, and the affected code is unknown beyond that component.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can be carried out remotely and is publicly disclosed, meaning attackers can readily target any exposed instance of the service. The lack of immediate vendor response further increases the window of exposure, making timely remediation critical.
OpenCVE Enrichment