Description
HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.
Problem types
Product status
Credits
dreizehnutters
References
www.exploit-db.com/exploits/51537 (ExploitDB-51537)
www.belden.com/.../device-software/hisecos-firewall-software (Official Product Webpage)
www.vulncheck.com/...e-escalation-via-user-role-modification (VulnCheck Advisory: HiSecOS 04.0.01 Privilege Escalation via User Role Modification)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.