Impact
The vulnerability is an arbitrary file overwrite in Funambol Zefiro Cloud version 32.0.2026011614, allowing an attacker to overwrite critical internal files through the file import process. This flaw can lead to arbitrary code execution or sensitive data exposure, classified as CWE‑22.
Affected Systems
Affected system is Funambol Zefiro Cloud version 32.0.2026011614. No other versions are specified in the data.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, placing it in the critical severity range. The EPSS score is below 1 %, indicating a low current likelihood of exploitation. The likely attack vector is via the file import interface, which may be exposed over the network; this is inferred from the fact that the file import process is mentioned as the mechanism for the overwrite. The issue is not listed in the CISA KEV catalog. Successful exploitation would allow an attacker to gain code execution or disclose information.
OpenCVE Enrichment