CVE-2025-4078
Wangshen SecGate 3600 g=log_export_file path traversal
Record summary
CVE-2025-4078 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 30, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SecGate 3600Browse Wangshen / SecGate 3600 | CVE List, VulnCheck | 2400 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWangshen SecGate 3600 Path Traversal Vulnerability
Wangshen SecGate 3600 2400 contains a path traversal caused by manipulation of the 'file_name' argument in '?g=log_export_file', letting remote attackers access arbitrary files, exploit requires remote access.
Impact
Remote attackers can access sensitive files on the system, potentially leading to information disclosure or system compromise.
Remediation
Implement input validation and sanitize 'file_name' parameter; update to the latest firmware version if available.
Source: ProjectDiscovery