Softing · Uagate Si · CVE-2019-11526
**Name of the Vulnerable Software and Affected Versions**
Softing uaGate SI version 1.60.01
**Description**
An issue was discovered that allows file path injection via a maintenance script executable with sudo privileges. This enables an attacker to write files with superuser privileges in specific locations.
**Recommendations**
For Softing uaGate SI version 1.60.01, consider restricting access to the maintenance script to prevent exploitation until a fix is available. As a temporary workaround, limit the use of sudo privileges for the script to minimize the risk of file path injection.