CVE-2025-4078
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 29, 2025
Updated: May 2, 2025
CWE ID 22
Summary
CVE-2025-4078 is a newly disclosed vulnerability affecting the Wangshen SecGate 3600 2400 system. The issue lies in the processing of the file 'log_export_file' and involves a path traversal vulnerability. Manipulation of the argument 'file_name' can be exploited to navigate outside intended directories. This vulnerability is considered problematic, as it can be exploited remotely, potentially allowing unauthorized access to sensitive information. The exploit for this vulnerability has been made public, increasing the risk of potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.