← back
CVE-2026-35077highCWE-73

Arbitrary file delete vulnerability in method ugw-delete-file

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

A feature that deletes files doesn't properly check what files users are allowed to delete, letting attackers with regular user access remove important system files they shouldn't touch.

Technical detail

The ugw-delete-file method fails to validate or restrict file paths provided by authenticated users, allowing path traversal attacks to delete arbitrary files on the system. An attacker with valid user credentials can exploit insufficient input validation to access and remove files outside intended directories.

Summary generated and translated by AI from the official description.
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N