PT-2025-27615 · Infinera · Infinera G42
Published
2025-07-02
·
Updated
2026-02-11
·
CVE-2025-27022
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Infinera G42 version R6.1.3
Description:
The issue allows remote authenticated users to download all OS files via HTTP requests due to a path traversal vulnerability in the WebGUI HTTP endpoint. This is caused by a lack or insufficient validation of user-supplied input, enabling authenticated users to access all files on the target machine file system that are readable to the user account used to run the httpd service.
Recommendations:
For Infinera G42 version R6.1.3, consider restricting access to the WebGUI HTTP endpoint until a patch is available, and ensure proper validation of user-supplied input to prevent path traversal attacks. As a temporary workaround, limit the privileges of the user account used to run the httpd service to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinera G42