PT-2024-12936 · Unknown · Qufirewall

Alan Li

+1

·

Published

2024-04-26

·

Updated

2025-09-24

·

CVE-2023-41290

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions QuFirewall versions prior to 2.4.1
Description A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
Recommendations For versions prior to 2.4.1, update to QuFirewall 2.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-41290

Affected Products

Qufirewall