Impact
Unauthenticated remote attackers can trigger a relative path traversal flaw in 4MOSAn Management Center to download arbitrary system files. This demonstrates an arbitrary file read vulnerability, exposing sensitive configuration and data files without credentials and posing a confidentiality risk.
Affected Systems
The vulnerability impacts 4MOSAn Security Technology’s 4MOSAn Management Center. All releases prior to version 20260621 are vulnerable; upgrading to 20260621 or later and performing the FreeBSD-GCB Management Center security upgrade is required to remediate.
Risk and Exploitability
With a CVSS score of 8.7, the flaw carries high risk. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, so widespread exploitation remains uncertain. Nonetheless, attackers can exploit the flaw over the network from any host that can reach the exposed Management Center, requiring no authentication and enabling read of any accessible file.
OpenCVE Enrichment