Vulnerabilities > CVE-2023-25650 - Unspecified vulnerability in ZTE Zxcloud Irai Firmware 6.03.04

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
zte

Summary

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

Vulnerable Configurations

Part Description Count
OS
Zte
2
Hardware
Zte
1