CVE-2026-74237
moderateArbitrary File Read via Argument Injection in GFI Exinda AI/ClearView Iperf Tool
GFI Exinda AI and ClearView versions prior to 7.6.5 contain an argument injection flaw (CWE-88) in the Tools Iperf Client feature, where the web_tools_cmd() function builds an iperf command line from the 'server' and 'options' parameters without sanitizing them. An authenticated attacker holding only the lowest (Unprivileged) access level can trigger the flaw by submitting a crafted Iperf Client request that injects arbitrary iperf flags into the command. By injecting the -F flag, the attacker causes the appliance to read an arbitrary file from its local filesystem and transmit its contents to an attacker-controlled server, potentially exposing configuration files or stored credentials. Only deployments of GFI Exinda AI or ClearView running versions earlier than 7.6.5 that allow low-privileged users to reach the Iperf Client tool are affected. There is no evidence of exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates the 30-day exploitation probability at about 0.2%.
What to do: Upgrade GFI Exinda AI and ClearView to version 7.6.5 or later. Until patched, restrict access to the Tools Iperf Client feature to trusted accounts, limit management-interface exposure to untrusted networks, and review appliance logs for unexpected iperf invocations or outbound connections to unknown hosts. Audit which files are readable by the appliance's service account to determine what an arbitrary file read could have exposed, including any credentials stored in configuration.
| GFI Exinda AI | before 7.6.5 |
| GFI ClearView | before 7.6.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary iperf flags. An authenticated attacker with Unprivileged (lowest-level) access can supply the iperf -F flag to read an arbitrary file from the system and transmit its contents to an attacker-controlled server.
- Weakness
- CWE-88
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.