CVE-2025-4078 is a path traversal vulnerability affecting Wangshen SecGate 3600 2400 devices, specifically within the handling of the ?g=log_export_file function and its file_name argument. Rated as Medium severity (CVSS 4.3), this vulnerability allows an unauthenticated remote attacker to potentially access sensitive files due to improper input validation, though the impact is limited to confidentiality. While there is no evidence of active exploitation, public exploit details are available through Nuclei templates, but it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wangshen | SecGate 3600 | 2400CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.