09/06/2026 |
HKCERT has identified a critical vulnerability (CVSS 9.8) in the authentication module of a popular enterprise firewall solution. The vulnerability allows unauthenticated remote attackers to bypass the administrative interface and gain full control of the firewall appliance.
Enterprise firewall appliances running firmware versions prior to 7.4.2. Multiple organisations in Hong Kong’s financial and healthcare sectors are confirmed to be using affected versions.
Successful exploitation could allow an attacker to:
This vulnerability represents a significant risk to Hong Kong organisations. We recommend treating this as a priority patch and coordinating with your vendor for emergency firmware updates if needed.