CVE-2023-25648: ZTE Zxcloud Irai

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.

Affected products

  • ZTE Zxcloud Irai: before 7.23.21 (fixed in 7.23.21)

Published 2023-12-14. Last modified 2026-06-17.