PT-2025-27273 · Marvell · Marvell Qconvergeconsole

Andrea Micalizzi

+1

·

Published

2025-06-27

·

Updated

2025-07-07

·

CVE-2025-6805

CVSS v3.1
9.1
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Marvell QConvergeConsole (affected versions not specified)

Description:

The issue concerns a directory traversal arbitrary file deletion vulnerability in the deleteEventLogFile function of Marvell QConvergeConsole. This allows for the deletion of arbitrary files. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-6805
ZDI-25-461

Affected Products

Marvell Qconvergeconsole