← Back

CVE-2025-27022

nvd nist
Published: Jul 2, 2025Modified: Feb 11, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 (Secondary)

Description

A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files via HTTP requests. Details: Lack or insufficient validation of user-supplied input allows authenticated users to access all files on the target machine file system that are readable to the user account used to run the httpd service.

Affected (1)

Products: Nokia: G42 Firmware
1 product
G42 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 6.1.3 to 7.1
Running on/withPlatform Versions
Nokia
G42
All versions

References (2)

Source: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
Third Party Advisory
Source: a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
Third Party Advisory

Timeline

No history available yet.