There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
2023-12-14T07:15:07.180
2025-01-28T15:36:03.663
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zte | zxcloud_irai | < 7.23.21 | Yes |
Application | zte | zxcloud_irai | - | No |