Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27023


Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted CLI commands. Details: The web interface based management of the Infinera G42 appliance enables the feature of executing a restricted set of commands. This feature also offers the option to execute a script-file already present on the target device. When a non-script or incorrect file is specified, the content of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.


Published

2025-07-02T10:15:22.540

Last Modified

2026-02-11T21:31:06.017

Status

Analyzed

Source

a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System nokia g42_firmware < 7.1 Yes
Hardware nokia g42 - No

References