CVE-2025-27022

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
02/07/2025
Last modified:
03/07/2025

Description

A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 <br /> allows remote authenticated users to download all OS files via HTTP <br /> requests.<br /> <br /> <br /> Details: <br /> <br /> Lack or insufficient validation of user-supplied input allows <br /> authenticated users to access all files on the target machine file <br /> system that are readable to the user account used to run the httpd <br /> service.