Junglewise Threat Intelligence

CVE-2026-74237: GFI Exinda AI and ClearView argument injection in Tools Iperf Client

CVE-2026-74237 · Severity: medium · CVSS 6.5 · Published 2026-09-04

Technologies: GFI ClearView, GFI Exinda AI. Vendors: GFI.

Executive brief

GFI Exinda AI and ClearView are network orchestration and management appliances used by enterprises to optimize and monitor network traffic. An authenticated attacker with low-level access can inject arbitrary flags into the Iperf diagnostic tool to read sensitive files from the system and exfiltrate them to an attacker-controlled server, potentially exposing configuration data and credentials.

Technical details

The vulnerability is an argument injection (CWE-88) in the web_tools_cmd() function, which constructs iperf diagnostic commands without sanitizing the server and options parameters. An authenticated attacker with unprivileged (lowest-level) access can inject the iperf -F flag to read arbitrary files from the filesystem and transmit their contents to a remote server. The attack requires authentication and network access to the web interface; no user interaction is needed. The vulnerable versions are before 7.6.5; patched versions are available.

Affected products

  • GFI Exinda AI before 7.6.5
  • GFI ClearView before 7.6.5

Timeline

  • 2026-09-04: disclosed

References

Related threats