A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.
| Software | From | Fixed in |
|---|---|---|
| nozominetworks / cmc | - | 25.5.0 |
| nozominetworks / guardian | - | 25.5.0 |