Where to buy | Partner Portal | eShop

Security Advisory

Cybersecurity

As IoT adoption continues to proliferate, cybersecurity has become one of the top priorities. Aten created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Aten's customers have steady, unambiguous resources to help them understand how Aten resolves or mitigates reported vulnerabilities.

Vulnerability Overview

CVE-2026-9776

ZDI-CAN-28505: ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability
A vulnerability has been discovered in ATEN Unizon versions prior to V2.7.264.001. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the writeFileToHttpServletResponse method.
The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM.

Security Patch
Download the latest security patch here:
Download the Security Patch

Acknowledgments
We thank Ahmed Y. Elmogy, in collaboration with the Zero Day Initiative (ZDI) by Trend Micro, for responsibly disclosing this vulnerability.

Release Date: 2026/06/24

Vulnerability Metrics

Vulnerability Scoring Details :

The vulnerability scores and vectors are listed below.