Published:2026/04/22  Last Updated:2026/04/22

JVN#00575116
Ziostation2 vulnerable to path traversal

Overview

Ziostation2 provided by Ziosoft, Inc. contains a path traversal vulnerability.

Products Affected

  • Ziostation2 v2.9.8.7 and earlier

Description

Ziostation2 provided by Ziosoft, Inc. contains the following vulnerability.

  • Path traversal (CWE-22)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Base Score 7.5
    • CVE-2026-40062

Impact

Sensitive information on the operating system may be obtained by a remote unauthenticated attacker.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
Ziosoft, Inc. Vulnerable 2026/04/22

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Yuta Miura of Five Drive Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-40062
JVN iPedia JVNDB-2026-000058