Loading
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
Use CWE-732, Zte vendor hub and Zxcloud Irai product page to widen CVE-2023-25648 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-21731, CVE-2023-41776 and CVE-2023-25650 for nearby disclosures in the same product family.