ZDI-25-465: (0Day) Marvell QConvergeConsole readObjectFromConfigFile Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Jun 27, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-6808.
Affected Software
1 affected component
Marvell QConvergeConsole
Event History
Jun 27, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-465?
The severity of ZDI-25-465 is rated 9.8 on the CVSS scale.
2
How do I fix ZDI-25-465?
To fix ZDI-25-465, you should apply the latest security patch provided by Marvell for QConvergeConsole.
3
What kind of attacks can exploit ZDI-25-465?
ZDI-25-465 allows remote attackers to execute arbitrary code without the need for authentication.
4
Which software is affected by ZDI-25-465?
ZDI-25-465 affects installations of Marvell QConvergeConsole.
5
Is authentication required to exploit ZDI-25-465?
No, authentication is not required to exploit ZDI-25-465.