CVE-2025-6796 is a directory traversal vulnerability in Marvell QConvergeConsole, allowing unauthenticated remote attackers to disclose sensitive information. This flaw, stemming from improper path validation in the getAppFileBytes method, enables information disclosure with SYSTEM privileges. Rated 7.5 HIGH on CVSS, it presents a significant risk due to its network-based attack vector and low complexity. While not yet in CISA KEV or having public exploit code, its high FAUCET Risk Score and extensive community discussion (20 mentions) indicate considerable attention and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.5.0.85CPE matchmatch criteria | cpe:2.3:a:marvell:qconvergeconsole:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.