CVE-2026-74237: GFI Exinda AI < 7.6.5 Argument Injection via Tools Iperf Client
GFI Exinda AI before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The webtoolscmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary iperf flags. An authenticated attacker with Unprivileged (lowest-level) access can supply the iperf -F flag to read an arbitrary file from the system and transmit its contents to an attacker-controlled server.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with Unprivileged, the lowest-level access, can exploit it. The vulnerable functionality is the Tools Iperf Client feature.
What does an attacker need to do to exploit it?
The attacker needs valid low-privilege authentication and must be able to provide values for the Iperf Client server and options parameters. They can inject iperf flags, including -F, to cause a system file's contents to be sent to an attacker-controlled server.
Are default deployments affected?
The available information does not state whether the Tools Iperf Client functionality is enabled or accessible by default. Exposure depends on whether unprivileged authenticated users can access that feature.
How can I determine whether I am affected?
Systems running GFI Exinda AI before version 7.6.5 are affected. Review access to the Tools Iperf Client and investigate Iperf invocations for injected flags, particularly use of the -F flag with unexpected file paths or external server destinations.