CVE-2025-24494

Path traversal may allow remote code execution using privileged account 
(requires device admin account, cannot be performed by a regular user). 
In combination with the 'Upload' functionality this could be used to 
execute an arbitrary script or possibly an uploaded binary. Remediation 
in Version 6.7.0, release date: 20-Oct-24.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
icscertCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---