PT-2025-48017 · Aicloud · Icloud

Nanyu Zhong

·

Published

2025-11-25

·

Updated

2025-11-26

·

CVE-2025-59366

CVSS v4.0
9.2
VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AiCloud versions 3.0.0.4 386 through 3.0.0.4 388 and 0.6 102
Description An authentication-bypass issue exists in AiCloud, triggered by an unintended side effect of the Samba functionality. This can allow execution of specific functions without proper authorization. The issue impacts critical router functions and allows bypass of authentication.
Recommendations AiCloud versions 3.0.0.4 386 through 3.0.0.4 388 should be updated. AiCloud version 0.6 102 should be updated.

Fix

OS Command Injection

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-59366

Affected Products

Icloud