CVE-2025-9639: AI3 Qbicrmgateway

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

Affected products

  • AI3 Qbicrmgateway: from 7.5.1, up to and including 8.5.03

Published 2025-08-29. Last modified 2026-06-17.