VYPR
Medium severity6.5NVD Advisory· Published Dec 14, 2023· Updated Jun 17, 2026

CVE-2023-25650

CVE-2023-25650

Description

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Zte/Zxcloud Irai2 versions
    cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zte:zxcloud_irai:*:*:*:*:*:*:*:*range: <7.23.30
    • (no CPE)range: All versions up to V7.23.23
  • ZXCLOUD/IRAIllm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.