HiSecOS 04.0.01 contains a privilege escalation...
High severity
Unreviewed
Published
Dec 18, 2025
to the GitHub Advisory Database
•
Updated Dec 18, 2025
Description
Published by the National Vulnerability Database
Dec 17, 2025
Published to the GitHub Advisory Database
Dec 18, 2025
Last updated
Dec 18, 2025
HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.
References