Security Advisory
Cybersecurity
As IoT adoption continues to proliferate, cybersecurity has become one of the top priorities. Aten created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Aten's customers have steady, unambiguous resources to help them understand how Aten resolves or mitigates reported vulnerabilities.
CVE-2026-9774
ZDI-CAN-28502: ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability
A vulnerability has been discovered in ATEN Unizon versions prior to V2.7.264.001. This vulnerability allows an authenticated remote attacker to delete arbitrary files on affected systems.
The specific flaw exists within the updateLicense method. The issue results from insufficient validation of a user-supplied path before it is used in file operations. An attacker can exploit this vulnerability to delete arbitrary files or cause a denial-of-service (DoS) condition on the affected system.
Security Patch
Download the latest security patch here:
Download the Security Patch
Acknowledgments
We thank Ahmed Y. Elmogy, in collaboration with the Zero Day Initiative (ZDI) by Trend Micro, for responsibly disclosing this vulnerability.
Release Date: 2026/06/24
Vulnerability Scoring Details :
The vulnerability scores and vectors are listed below.
| Severity | CVSS Score | Vector |
|---|---|---|
| MEDIUM | 5.5 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
