Record summary

CVE-2025-4078 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 30, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheck2400affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWangshen SecGate 3600 Path Traversal Vulnerability

Wangshen SecGate 3600 2400 contains a path traversal caused by manipulation of the 'file_name' argument in '?g=log_export_file', letting remote attackers access arbitrary files, exploit requires remote access.

Impact

Remote attackers can access sensitive files on the system, potentially leading to information disclosure or system compromise.

Remediation

Implement input validation and sanitize 'file_name' parameter; update to the latest firmware version if available.

AuthorsArk
Template tagscvecve2025wangshenlfitraversalvulnvkev
FOFA: fid="1Lh1LHi6yfkhiO83I59AYg=="

Source: ProjectDiscovery

References

5