CVE-2023-25650: ZTE Zxcloud Irai

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.

Affected products

  • ZTE Zxcloud Irai: before 7.23.30 (fixed in 7.23.30)

Published 2023-12-14. Last modified 2026-06-17.