CVE-2025-24494
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
05/03/2025
Last modified:
05/03/2025
Description
Path traversal may allow remote code execution using privileged account <br />
(requires device admin account, cannot be performed by a regular user). <br />
In combination with the &#39;Upload&#39; functionality this could be used to <br />
execute an arbitrary script or possibly an uploaded binary. Remediation <br />
in Version 6.7.0, release date: 20-Oct-24.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH



