Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Marvell QConvergeConsole. This issue arises from a directory traversal flaw in the saveAsText method, where user-supplied paths are not properly validated before being used in file operations. As a result, remote attackers can execute arbitrary code on the affected system with SYSTEM privileges. Notably, this vulnerability can be exploited without authentication.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system, with the executed code running in the context of the SYSTEM user.

Remediation

Marvell QConvergeConsole is no longer supported or recommended by the vendor. The product has reached End of Life and End of Support status after version 5.5.0.85 was released in January 2022.

Added: Jul 7, 2025, 3:47 PM
Updated: Jul 7, 2025, 3:47 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
10.0
exploitability
4.7
remediation
3.7
relevance
0.2
threat
0.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.