CVE-2025-43928

Published Apr 20, 2025

Last updated 4 days ago

CVSS medium 5.8
Infodraw MRS

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-43928 is a path traversal vulnerability found in Infodraw Media Relay Service (MRS) 7.1.0.0. Specifically, the MRS web server (running on port 12654) is susceptible to arbitrary file reading due to improper input validation in the username field. By using "../" sequences, an attacker can access files outside the intended directory. Successful exploitation of this vulnerability allows an unauthenticated attacker to read sensitive files on the system. For example, reading the ServerParameters.xml file could reveal administrator credentials, potentially stored in cleartext or as MD5 hashes. This vulnerability affects both Windows and Linux versions of MRS.

Description
In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-24
nvd@nist.gov
CWE-22

Social media

Hype score
Not currently trending

Configurations