CVE-2020-29026: Secomea Gatemanager 4250 Firmware

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.

Affected products

  • Secomea Gatemanager 4250 Firmware: before 9.0i (fixed in 9.0i)
  • Secomea Gatemanager 4260 Firmware: before 9.0i (fixed in 9.0i)
  • Secomea Gatemanager 8250 Firmware: before 9.2c (fixed in 9.2c)
  • Secomea Gatemanager 9250 Firmware: before 9.0i (fixed in 9.0i)

Published 2021-02-15. Last modified 2026-06-17.