Safeguard
Vulnerability Analysis

WinRAR, FileZen, and IGEL OS: Three Unrelated Products, Three Broken Trust Boundaries

An APT-linked WinRAR path traversal, a FileZen command injection hiding behind its own antivirus feature, and a Secure Boot bypass in IGEL OS show KEV's reach beyond headline platforms.

Safeguard Research Team
5 min read

Three unrelated products from three unrelated vendors — an archive utility used on hundreds of millions of desktops, a Japanese file-exchange appliance, and a specialized thin-client operating system — each had a distinct trust boundary broken this year, and each was confirmed exploited in ways specific to its own category of software.

CVECVSSProductTrust boundary broken
CVE-2025-62187.8RARLAB WinRARFile path handling during extraction
CVE-2026-251088.8Soliton Systems K.K FileZenAuthenticated request handling
CVE-2025-478274.6IGEL OSCryptographic signature verification at boot

Why WinRAR's path traversal bug earned attention from an actual APT group

CVE-2025-6218 is a directory traversal vulnerability in how WinRAR handles file paths embedded within archive files. A crafted path inside an otherwise ordinary-looking archive can cause the extraction process to traverse outside the intended destination folder, letting an attacker place files wherever they choose on the victim's file system — a foothold sufficient for remote code execution once the resulting files can be triggered to run. Exploitation requires the target to open a malicious archive or visit a malicious page, meaning it's a one-click rather than zero-click bug, but WinRAR's sheer ubiquity as the default archive tool on countless Windows machines makes that click a low bar to clear through a routine-looking phishing lure. Multiple independent write-ups, including from foresiet and SecPod, tie active exploitation of this specific CVE to APT-C-08, giving this bug a documented espionage-actor pedigree rather than leaving it as a purely theoretical finding — a detail that should reframe how urgently any organization treats a "just an archive tool" update.

Why FileZen's command injection requires a logged-in user, and why that's not much comfort

CVE-2026-25108 in Soliton Systems' FileZen, a managed file transfer and exchange appliance widely used in Japan, is an OS command injection vulnerability that a logged-in user can trigger via a specially crafted HTTP request when the product's Antivirus Check Option is enabled — meaning the very feature meant to scan uploaded files for malware is the component that mishandles input and allows command injection. Requiring authentication sounds like a meaningful barrier until you consider that FileZen exists specifically to let outside parties — clients, partners, contractors — exchange files with an organization, meaning its population of "logged-in users" plausibly extends well beyond internal staff to a wide and only partially trusted external circle. A command injection bug reachable by any account in that broader population, gated behind a security feature ironically named for the exact threat class it was meant to catch, describes an appliance where the authentication requirement filters out far less risk than it initially appears to.

Why IGEL OS's low CVSS score undersells what Secure Boot bypass actually means

CVE-2025-47827 carries the lowest severity score of the three at 4.6, medium, yet describes something structurally serious: the igel-flash-driver module improperly verifies a cryptographic signature, using a key past its expiration date, which ultimately allows a crafted root filesystem to be mounted from an unverified SquashFS image — a full Secure Boot bypass. IGEL OS is a purpose-built operating system for thin clients, devices specifically deployed because organizations want a locked-down, verifiably trustworthy endpoint with minimal attack surface. Defeating Secure Boot on exactly that category of device undermines the entire premise of choosing a thin-client architecture in the first place, regardless of what CVSS's exploitability metrics say about the practical difficulty of pulling it off — a lower score here reflects constrained exploit conditions, not a smaller consequence once achieved.

What to check this week

  • Update WinRAR to the patched version referenced in the vendor's own advisory immediately across every endpoint, given documented APT-C-08 exploitation and the tool's near-universal presence on Windows machines.
  • Disable or carefully scope the FileZen Antivirus Check Option pending a confirmed patch, since that specific feature is the vulnerable code path for the command injection bug.
  • Audit the full population of external accounts with FileZen login access, not just internal staff, given the appliance's purpose of facilitating outside file exchange.
  • Upgrade IGEL OS to version 11 or later and verify Secure Boot is functioning as expected on deployed thin clients rather than assuming firmware-level protections remain intact by default.

A closing note on why unrelated single findings still deserve full attention

None of these three vulnerabilities shares a vendor, a product category, or an attack technique with the others, and none produced a multi-CVE cluster the way a single vendor's product line sometimes does elsewhere in this series. That's precisely the point worth internalizing: CISA's Known Exploited Vulnerabilities catalogue isn't dominated only by headline platforms with repeat findings — it also reflects genuinely distinct, standalone compromises of an archive tool, a file exchange appliance, and an endpoint operating system, each requiring the same investigative and remediation attention as any cluster, in proportion to what it actually protects.

How Safeguard helps

Safeguard's continuous inventory treats every confirmed-exploited finding with the same baseline priority regardless of whether it arrives as part of a large vendor cluster or as an isolated single-CVE entry, ensuring that a niche file-exchange appliance or a specialized thin-client OS doesn't receive less scrutiny simply because it lacks the visibility of a headline platform.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.