CVE-2025-27023: Improper Input Validation in Infinera G42
Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted CLI commands.
Details: The web interface based management of the Infinera G42 appliance enables the feature of executing a restricted set of commands. This feature also offers the option to execute a script-file already present on the target device. When a non-script or incorrect file is specified, the content of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27023?
CVE-2025-27023 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive OS files.
How do I fix CVE-2025-27023?
To mitigate CVE-2025-27023, ensure that input validation is properly implemented in all CLI commands to restrict access.
Who is affected by CVE-2025-27023?
CVE-2025-27023 affects the Infinera G42 appliance running version R6.1.3.
What type of vulnerability is CVE-2025-27023?
CVE-2025-27023 is a lack of input validation vulnerability targeting the WebGUI CLI management feature.
Can CVE-2025-27023 be exploited remotely?
Yes, CVE-2025-27023 can be exploited by remote authenticated users through crafted CLI commands.