Directory Traversal Information Disclosure in Marvell QConvergeConsole
CVE-2025-6803
7.5HIGH
What is CVE-2025-6803?
The Marvell QConvergeConsole has a directory traversal vulnerability that allows remote attackers to disclose sensitive information. The flaw originates in the compressDriverFiles method, where insufficient validation of user-supplied paths leads to unauthorized file access. This enables attackers to extract confidential data without requiring authentication, posing a significant risk to the integrity of the affected installations.
Affected Version(s)
QConvergeConsole 5.5.0.78