ZDI-25-466: (0Day) Marvell QConvergeConsole readNICParametersFromFile Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Jun 27, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-6809.
Affected Software
1 affected component
Marvell QConvergeConsole
Event History
Jun 27, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-466?
The severity of ZDI-25-466 is rated as 9.8 on the CVSS scale.
2
How do I fix ZDI-25-466?
To fix ZDI-25-466, update your Marvell QConvergeConsole installation to the latest security patch provided by the vendor.
3
What types of attacks can exploit ZDI-25-466?
ZDI-25-466 allows remote attackers to execute arbitrary code on the affected installations.
4
Is authentication required to exploit ZDI-25-466?
No, authentication is not required to exploit ZDI-25-466.
5
What software is affected by ZDI-25-466?
The vulnerability ZDI-25-466 affects Marvell QConvergeConsole installations.