Directory Traversal Information Disclosure in Marvell QConvergeConsole
CVE-2025-6807
5.3MEDIUM
What is CVE-2025-6807?
Marvell QConvergeConsole has a directory traversal vulnerability within the getDriverTmpPath method, which lacks proper validation of user-supplied paths. This flaw permits remote attackers to access sensitive information without authentication, potentially affecting installations and compromising data integrity. Attackers can exploit this security weakness to gain insights into the system's files and directories in the context of SYSTEM, heightening risks associated with unauthorized access.
Affected Version(s)
QConvergeConsole 5.5.0.78