ZeroHour

CVE-2023-25650

CVSS 3.1
6.5 medium
EPSS
<1%p46
Published
()
Modified
Description

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

Vendors
zte
Products
zxcloud irai
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.