CVE-2025-27085

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.
Configurations

No configuration.

History

09 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-22
Summary
  • (es) Existen múltiples vulnerabilidades en la interfaz de gestión web de AOS-10 GW y AOS-8 Controller/Mobility Conductor. La explotación exitosa de estas vulnerabilidades podría permitir que un atacante remoto autenticado descargue archivos arbitrarios del sistema de archivos de un dispositivo afectado.

08 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 17:15

Updated : 2025-04-09 18:15


NVD link : CVE-2025-27085

Mitre link : CVE-2025-27085

CVE.ORG link : CVE-2025-27085


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')