CVE Vulnerabilities

CVE-2023-25650

Published: Dec 14, 2023 | Modified: Dec 19, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

Affected Software

Name Vendor Start Version End Version
Zxcloud_irai_firmware Zte * 7.23.30 (excluding)

References