NONE · 0

CVE-2026-12339

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite...

Vulnerability Description

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-12339?

CVE-2026-12339 is a documented vulnerability. A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite...

How severe is CVE-2026-12339?

CVSS scoring is not yet available for CVE-2026-12339. Check NVD for updates.

Is there a patch for CVE-2026-12339?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.