Description
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
Published: 2026-08-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Read
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated remote attackers can trigger a relative path traversal flaw in 4MOSAn Management Center to download arbitrary system files. This demonstrates an arbitrary file read vulnerability, exposing sensitive configuration and data files without credentials and posing a confidentiality risk.

Affected Systems

The vulnerability impacts 4MOSAn Security Technology’s 4MOSAn Management Center. All releases prior to version 20260621 are vulnerable; upgrading to 20260621 or later and performing the FreeBSD-GCB Management Center security upgrade is required to remediate.

Risk and Exploitability

With a CVSS score of 8.7, the flaw carries high risk. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, so widespread exploitation remains uncertain. Nonetheless, attackers can exploit the flaw over the network from any host that can reach the exposed Management Center, requiring no authentication and enabling read of any accessible file.

Generated by OpenCVE AI on August 24, 2026 at 05:50 UTC.

Remediation

Vendor Solution

Upgrade to version 20260621 or later and perform the FreeBSD-GCB Management Center security upgrade


OpenCVE Recommended Actions

  • Upgrade to version 20260621 or later and apply the FreeBSD-GCB Management Center security upgrade.
  • Restrict external network access to the Management Center using firewall rules or VPN to limit exposure to trusted hosts.
  • Configure audit logging to capture and alert on file retrieval requests that resemble path‑traversal attempts.

Generated by OpenCVE AI on August 24, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared 4mosan Security Technology
4mosan Security Technology 4mosan Management Center
Vendors & Products 4mosan Security Technology
4mosan Security Technology 4mosan Management Center

Mon, 24 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Description 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
Title 4MOSAn Security Technology|4MOSAn Management Center - Arbitrary File Read
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

4mosan Security Technology 4mosan Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-24T16:38:10.832Z

Reserved: 2026-08-24T02:02:24.831Z

Link: CVE-2026-78212

cve-icon Vulnrichment

Updated: 2026-08-24T16:38:03.300Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T04:16:59.660

Modified: 2026-08-26T16:40:21.650

Link: CVE-2026-78212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:51Z

Weaknesses
  • CWE-23

    Relative Path Traversal