CVE-2018-25312
MEDIUMLifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution
Title source: cnaDescription
LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.
Exploits (1)
Scores
CVSS v3
6.5
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
LifeSize/ClearSea
3.1.4
Published
Apr 29, 2026
Tracked Since
Apr 30, 2026