CVE-2019-12803: Hunesion I-Onenet

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as running a system command.

Affected products

  • Hunesion I-Onenet: from 3.0.7, up to and including 3.0.53; from 4.0.4, up to and including 4.0.16

Published 2019-07-10. Last modified 2026-06-17.