CVE-2025-27022: Path Traversal Vulnerability in Infinera G42
A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files via HTTP requests.
Details:
Lack or insufficient validation of user-supplied input allows authenticated users to access all files on the target machine file system that are readable to the user account used to run the httpd service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27022?
CVE-2025-27022 has been rated as a critical vulnerability due to the potential for unauthorized access to sensitive files.
How do I fix CVE-2025-27022?
To mitigate CVE-2025-27022, ensure that adequate input validation is implemented on the WebGUI HTTP endpoint and restrict file access permissions for authenticated users.
Who is affected by CVE-2025-27022?
CVE-2025-27022 affects users of Infinera G42 version R6.1.3 and requires immediate attention from system administrators.
Can CVE-2025-27022 be exploited remotely?
Yes, CVE-2025-27022 can be exploited remotely by authenticated users, allowing them to download all OS files.
What types of attacks are possible due to CVE-2025-27022?
CVE-2025-27022 enables path traversal attacks, allowing authenticated users to access files outside of the intended directory.