WaveStore WaveView Client Path Traversal Vulnerability Allowing Arbitrary File Access on WaveStore Server

Vulnerability

A path traversal vulnerability has been identified in the WaveView client, which allows high-privileged users to read or delete any file on the connected WaveStore Server. This issue arises in the 'ilog' script, which is executed with root privileges. The vulnerability affects all versions of WaveStore Server prior to 6.44.44.

Impact

Exploitation of this vulnerability could lead to unauthorized reading or deletion of files on the WaveStore Server, with the potential for significant disruption depending on the nature of the files accessed or removed.

Remediation

Users can upgrade to WaveStore Server version 6.44.44 or later to address this vulnerability.

Added: Dec 16, 2025, 1:17 PM
Updated: Dec 16, 2025, 2:12 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.8
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.