Path Traversal Vulnerability in Infinera G42 WebGUI HTTP Endpoint
CVE-2025-27022

7.5HIGH

Key Information:

Vendor

Infinera

Status
Vendor
CVE Published:
2 July 2025

What is CVE-2025-27022?

A path traversal vulnerability exists in the WebGUI HTTP endpoint of Infinera G42 version R6.1.3. This flaw allows remote authenticated users to exploit insufficient validation of user input, enabling them to download any OS files accessible to their user account through crafted HTTP requests. This vulnerability poses a significant risk as it allows unauthorized access to sensitive system files, potentially leading to further system exploitation.

Affected Version(s)

G42 6.1.3 < 7.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Agenzia per la Cybersicurezza Nazionale
.