PT-2025-27263 · Marvell · Marvell Qconvergeconsole

Andrea Micalizzi

+1

·

Published

2025-06-27

·

Updated

2025-07-07

·

CVE-2025-6795

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Marvell QConvergeConsole (affected versions not specified)
Description: The issue is related to a directory traversal information disclosure vulnerability in the getFileUploadSize function. This allows for potential information disclosure. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-6795
ZDI-25-455

Affected Products

Marvell Qconvergeconsole