Executive brief
GFI Exinda AI and ClearView are network orchestration and management appliances used by enterprises to optimize and monitor network traffic. An authenticated attacker with low-level access can inject arbitrary flags into the Iperf diagnostic tool to read sensitive files from the system and exfiltrate them to an attacker-controlled server, potentially exposing configuration data and credentials.
Technical details
The vulnerability is an argument injection (CWE-88) in the web_tools_cmd() function, which constructs iperf diagnostic commands without sanitizing the server and options parameters. An authenticated attacker with unprivileged (lowest-level) access can inject the iperf -F flag to read arbitrary files from the filesystem and transmit their contents to a remote server. The attack requires authentication and network access to the web interface; no user interaction is needed. The vulnerable versions are before 7.6.5; patched versions are available.
Affected products
- GFI Exinda AI before 7.6.5
- GFI ClearView before 7.6.5
Timeline
- 2026-09-04: disclosed