Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27023


Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted CLI commands. Details: The web interface based management of the Infinera G42 appliance enables the feature of executing a restricted set of commands. This feature also offers the option to execute a script-file already present on the target device. When a non-script or incorrect file is specified, the content of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.


Published

2025-07-02T10:15:22.540

Last Modified

2025-07-03T15:13:53.147

Status

Awaiting Analysis

Source

a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20

Affected Vendors & Products

-


References