CVE-2023-25951
published 2024-02-14CVE-2023-25951: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to…
PriorityP426medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.23%
13.5th percentile
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | killer | < 3.1423.712 | 3.1423.712 |
| intel | proset_wireless | < 22.240 | 22.240 |
| intel_proset | wireless_and_intel_killer_wi-fi_software | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ghsa7.5HIGH
osv6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
FUXA Affected by a Path Traversal Sanitization Bypass
ghsa·2026-02-10·CVSS 7.5
CVE-2026-25951 [HIGH] CWE-184 FUXA Affected by a Path Traversal Sanitization Bypass
FUXA Affected by a Path Traversal Sanitization Bypass
### Summary
A flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protections. By using nested traversal sequences (e.g., ....//), an attacker can write arbitrary files to the server filesystem, including sensitive directories like runtime/scripts. This leads to Remote Code Execution (RCE) when the server reloads the malicious scripts. It is a new vulnerability a patch bypass for the sanitization in the last release .
### Details
This report describes a new, distinct vulnerability that differs from previous Path Traversal advisories (such as CVE-2023-31718) in several ways:
Patch Bypass (Regression): The vulnerability circumvents the existing sanitization
GHSA
GHSA-w9vp-f95x-pq8m: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22
ghsa_unreviewed·2024-10-29
CVE-2023-25951 [MEDIUM] CWE-20 GHSA-w9vp-f95x-pq8m: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.
OSV
CVE-2023-25951: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22
osv·2024-02-14·CVSS 6.7
CVE-2023-25951 [MEDIUM] CVE-2023-25951: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22
Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-14
Published