CVE-2023-25650 MEDIUM

CVE-2023-25650: Arbitrary File Download Vulnerability in ZTE ZXCLOUD iRAI

Vendor Zte
Product ZXCLOUD iRAI
Weakness CWE-20 · Input validation
Published December 14, 2023
Last update August 2, 2024

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

Key dates

02Disclosure timeline

December 14, 2023 CVE published
August 2, 2024 Record updated