Medium severity6.5NVD Advisory· Published Dec 14, 2023· Updated Jun 17, 2026
CVE-2023-25648
CVE-2023-25648
Description
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:*range: <7.23.21
- (no CPE)
- (no CPE)range: All versions up to V7.23.20
Patches
Vulnerability mechanics
References
1- support.zte.com.cn/support/news/LoopholeInfoDetail.aspxnvdVendor Advisory
News mentions
0No linked articles in our index yet.