CVE-2014-0358: Xangati Software Release

High severity, CVSS 7.8. EPSS: 5.9% chance of exploitation in the next 30 days.

Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/MGConfigData, (2) the download parameter in a download action to servlet/MGConfigData, (3) the download parameter in a port_svc action to servlet/MGConfigData, (4) the file parameter in a getfile action to servlet/Installer, or (5) the binfile parameter to servlet/MGConfigData.

Affected products

  • Xangati Xangati Software Release: affected versions not specified
  • Xangati Xangati Xnr: affected versions not specified

Published 2014-04-15. Last modified 2026-06-17.