Impact
An authenticated attacker with unprivileged (lowest-level) access can inject arbitrary iperf flags into the system command because the web_tools_cmd() function constructs the iperf command from unsanitized server and options parameters. By supplying the iperf -F flag, the attacker can read any accessible file on the host and transmit its contents to a server under the attacker’s control, thereby exposing sensitive data.
Affected Systems
The vulnerability affects GFI Software’s GFI Exinda AI and GFI ClearView running any version prior to 7.6.5. Users should verify their deployed instance’s version and apply the correct patch if they are operating an affected release.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as high severity. Although no EPSS score is reported and the vulnerability is not listed in CISA’s KEV catalog, the exploit requires only a low‑privilege authenticated session and a web interface for command input, making it relatively straightforward for an attacker who has gained basic access. Consequently, the risk of an attacker exfiltrating confidential files remains significant until the service is updated or the feature disabled.
OpenCVE Enrichment