High severity7.5NVD Advisory· Published Jul 2, 2025· Updated Jun 17, 2026
CVE-2025-27022
CVE-2025-27022
Description
A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files via HTTP requests.
Details:
Lack or insufficient validation of user-supplied input allows authenticated users to access all files on the target machine file system that are readable to the user account used to run the httpd service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- euvd.enisa.europa.eu/vulnerability/CVE-2025-27022nvdThird Party Advisory
- www.cvcn.gov.it/cvcn/cve/CVE-2025-27022nvdThird Party Advisory
News mentions
0No linked articles in our index yet.