CVE-2025-9639
7.5Ai3 · QbiCRMGateway
Ai3 QbiCRMGateway contains a relative path traversal vulnerability that permits unauthenticated remote attackers to read arbitrary files from the underlying system.
Executive summary
An unauthenticated remote file reading vulnerability in Ai3 QbiCRMGateway poses a significant risk of sensitive data exposure and system compromise.
Vulnerability
This flaw is a relative path traversal vulnerability (CWE-23) that allows unauthenticated remote attackers to bypass security controls and download arbitrary system files. The vulnerability can be exploited over the network without requiring any user interaction or authentication.
Business impact
The ability for an unauthenticated attacker to read arbitrary files can lead to the exposure of sensitive configuration data, credentials, or proprietary information stored on the affected server. With a CVSS score of 7.5, this vulnerability is classified as High severity, as it facilitates unauthorized access to system resources that could lead to further exploitation or complete system compromise.
Remediation
Immediate Action: Update the QbiCRMGateway software to version v8.5.04 or later, or apply the specific security patch provided by the vendor.
Proactive Monitoring: Review web server and application access logs for unusual patterns, such as directory traversal sequences (e.g., ../) in URL parameters or unexpected file access requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block directory traversal attempts and suspicious input patterns targeting the gateway.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
Given the severity of this vulnerability and the ease with which it can be exploited by unauthenticated actors, organizations must prioritize the application of the vendor provided update. Failure to patch the affected QbiCRMGateway instances leaves systems exposed to potential data exfiltration and unauthorized information disclosure. Ensure that all systems running versions 7.5.1 through 8.5.03 are updated to version v8.5.04 or later immediately.
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 8.5.04 per CVE record