CVE-2026-74237: GFI Exinda AI < 7.6.5 Argument Injection via Tools Iperf Client

Published Sep 4, 2026
·
Updated

GFI Exinda AI before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The webtoolscmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary iperf flags. An authenticated attacker with Unprivileged (lowest-level) access can supply the iperf -F flag to read an arbitrary file from the system and transmit its contents to an attacker-controlled server.

Affected Software

1 affected component
GFI Exinda AI<7.6.5

Event History

Sep 4, 2026
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user with Unprivileged, the lowest-level access, can exploit it. The vulnerable functionality is the Tools Iperf Client feature.

2

What does an attacker need to do to exploit it?

The attacker needs valid low-privilege authentication and must be able to provide values for the Iperf Client server and options parameters. They can inject iperf flags, including -F, to cause a system file's contents to be sent to an attacker-controlled server.

3

Are default deployments affected?

The available information does not state whether the Tools Iperf Client functionality is enabled or accessible by default. Exposure depends on whether unprivileged authenticated users can access that feature.

4

How can I determine whether I am affected?

Systems running GFI Exinda AI before version 7.6.5 are affected. Review access to the Tools Iperf Client and investigate Iperf invocations for injected flags, particularly use of the -F flag with unexpected file paths or external server destinations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203