CVE-2026-40062 is a path traversal vulnerability affecting Ziostation2 version 2.9.8.7 and earlier that allows remote, unauthenticated attackers to access sensitive operating system information. The vulnerability has a CVSS score of 7.5 (HIGH), with a network-based attack vector requiring no special privileges or user interaction, making it easily exploitable. While the vulnerability poses a significant confidentiality risk through information disclosure, it does not enable attackers to modify systems or cause denial of service. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score indicating relatively low prevalence in active exploitation campaigns. Organizations running Ziostation2 should prioritize patching to versions after 2.9.8.7 to mitigate this high-severity information disclosure risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.9.8.7CPE matchmatch criteria | cpe:2.3:a:zio:ziostation2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.