CVE-2026-101071 Acrel Electric Unet Web Service 文件上传漏洞
影响攻击者可远程上传任意文件,可能导致服务器被控制
Acrel Electric Unet Web Service 的 /exchange/attachment/upload 上传接口存在不受限制的文件上传漏洞。攻击者可通过操纵 File 参数上传任意文件,且该漏洞利用方式已被公开披露。厂商已被告知但未作任何回应。
影响范围
Acrel Electric Unet Web Service 至 20260814 版本(含)受影响,具体受影响版本范围暂无更详细的公开信息。
漏洞详情
该漏洞属于不受限制的文件上传(Unrestricted Upload)类型,成因是上传接口未对上传文件的类型、扩展名或内容进行有效校验。攻击者可构造请求操纵 File 参数,将任意文件(如 WebShell)上传至服务器。攻击可远程发起,无需本地访问。
利用条件与风险
利用前提是目标系统的上传接口可被远程访问,且无需身份认证或认证可绕过(具体条件暂无公开信息)。由于利用方式已公开,实战中被扫描和利用的风险较高。
修复建议
官方修复方案暂无公开信息,厂商未作回应。临时缓解措施建议:限制上传接口的访问来源、对上传文件类型与扩展名进行严格白名单校验、将上传目录置于 Web 根目录之外并禁止执行脚本。
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.