CVE-2023-25648: ZTE Zxcloud Irai
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
Affected products
- ZTE Zxcloud Irai: before 7.23.21 (fixed in 7.23.21)
Published 2023-12-14. Last modified 2026-06-17.