CVE-2025-27937

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 22

Summary

CVE-2025-27937 is a path traversal vulnerability affecting Quick Agent V3 and V2. This issue allows a remote attacker with login access to the product to access arbitrary files outside of the restricted directory. The vulnerability stems from the software's failure to properly limit file access within the specified directory. Successful exploitation could result in the attacker gaining unauthorized access to sensitive data or system configurations. It is crucial that affected users apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share