CVE-2025-27023: Improper Input Validation in Infinera G42

Published Jul 2, 2025
·
Updated

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted CLI commands.

Details: The web interface based management of the Infinera G42 appliance enables the feature of executing a restricted set of commands. This feature also offers the option to execute a script-file already present on the target device. When a non-script or incorrect file is specified, the content of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.

Affected Software

3 affected components
Infinera G42
All of the following
Nokia G42 Firmware>=6.1.3<7.1
Nokia G42

Event History

Jul 2, 2025
CVE Published
via MITRE·09:07 AM
Data Sourced
via MITRE·09:07 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-27023?

CVE-2025-27023 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive OS files.

2

How do I fix CVE-2025-27023?

To mitigate CVE-2025-27023, ensure that input validation is properly implemented in all CLI commands to restrict access.

3

Who is affected by CVE-2025-27023?

CVE-2025-27023 affects the Infinera G42 appliance running version R6.1.3.

4

What type of vulnerability is CVE-2025-27023?

CVE-2025-27023 is a lack of input validation vulnerability targeting the WebGUI CLI management feature.

5

Can CVE-2025-27023 be exploited remotely?

Yes, CVE-2025-27023 can be exploited by remote authenticated users through crafted CLI commands.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2025-27023 - Improper Input Validation in Infinera G42 - SecAlerts