CVE-2026-78212: 4MOSAn Security Technology|4MOSAn Management Center - Arbitrary File Read
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
4MOSAn Management Centerto a version that resolves this vulnerability.Fixed in 20260621
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker who can reach the affected 4MOSAn Management Center service may exploit it. No credentials or user interaction are required.
What is the likely impact of successful exploitation?
An attacker can use relative path traversal to download arbitrary system files accessible to the affected service. The provided severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
How can I tell whether my deployment may be exposed?
Deployments running 4MOSAn Management Center that are remotely reachable should be considered potentially exposed based on the available information. The provided data does not identify affected versions, fixed versions, or a specific vulnerable endpoint.