Medium severity6.5NVD Advisory· Published Jul 2, 2025· Updated Jun 17, 2026
CVE-2025-27023
CVE-2025-27023
Description
Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted CLI commands.
Details: The web interface based management of the Infinera G42 appliance enables the feature of executing a restricted set of commands. This feature also offers the option to execute a script-file already present on the target device. When a non-script or incorrect file is specified, the content of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- euvd.enisa.europa.eu/vulnerability/CVE-2025-27023nvdThird Party Advisory
- www.cvcn.gov.it/cvcn/cve/CVE-2025-27023nvdThird Party Advisory
News mentions
0No linked articles in our index yet.