Acrel Electrical · Unet Web Service · CVE-2026-101071
**Name of the Vulnerable Software and Affected Versions**
Acrel Electric Unet Web Service versions prior to 20260814
**Description**
A remote unrestricted upload issue exists within the Upload Endpoint component. By manipulating the `File` argument at the '/exchange/attachment/upload' endpoint, an attacker can upload files without proper restrictions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict access to the '/exchange/attachment/upload' endpoint to minimize the risk of exploitation.