Record summary

CVE-2018-25312 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.1.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBLifeSize ClearSea 3.1.4 - Directory TraversalExploitDB exploitby rsp3arNot analyzed1 file
ExploitDB

PoC details

References

3