← Back

CVE-2023-25650

nvd nist
Published: Dec 14, 2023Modified: Jan 28, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

Affected (1)

Products: Zte: Zxcloud Irai
1 product
Zxcloud Irai
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.23.30
Running on/withPlatform Versions
Zte
Zxcloud Irai
All versions

References (2)

Timeline

No history available yet.