CVE-2025-25685: Path Traversal
An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25685?
CVE-2025-25685 has been classified as a high-severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2025-25685?
To remediate CVE-2025-25685, users should update their GL-Inet Beryl AX firmware to the latest version that addresses this vulnerability.
What is the impact of CVE-2025-25685 on GL-Inet Beryl AX devices?
CVE-2025-25685 allows attackers to exploit symbolic links to download arbitrary files from the device's file system, compromising sensitive data.
Can CVE-2025-25685 be exploited remotely?
Yes, CVE-2025-25685 can be exploited remotely if the device is configured to share files over Samba without appropriate security measures.
Who is affected by CVE-2025-25685?
CVE-2025-25685 affects users of GL-Inet Beryl AX GL-MT3000 running version 4.7.0 and earlier that utilize Samba shares.