7.8
CVSSv3

CVE-2023-25648

Published: 14/12/2023 Updated: 19/12/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

zte zxcloud_irai_firmware