Arbitrary File Reading Vulnerability in QbiCRMGateway by Ai3
CVE-2025-9639

8.7HIGH

Key Information:

Vendor

Ai3

Vendor
CVE Published:
29 August 2025

What is CVE-2025-9639?

The QbiCRMGateway, developed by Ai3, is susceptible to an Arbitrary File Reading vulnerability. This flaw permits unauthenticated remote attackers to exploit Relative Path Traversal methods, enabling them to download sensitive system files without proper authorization. As a result, attackers can potentially access private and confidential information stored on the server, posing a significant risk to the integrity and security of affected systems.

Affected Version(s)

QbiCRMGateway 7.5.1 <= 8.5.03

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9639 : Arbitrary File Reading Vulnerability in QbiCRMGateway by Ai3