Security Advisory

CVE-2025-41758

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-09 08:16:30
Last updated 2026-03-09 20:14:05
Assigner CERTVDE
State PUBLISHED

Description

A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.