go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Ai3|QbiCRMGateway - Arbitrary File Reading through Path Traversal

TVN ID TVN-202508007
CVE ID CVE-2025-9639
CVSS 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products QbiCRMGateway version from 7.5.1 to 8.5.03
Description The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
Solution Update to version v8.5.04 or later, or install the patch
Credit Huding(DEVCORE)
Public Date 2025-08-29
Top