CVE-2025-59784 PUBLISHED

Log Pollution - Control Characters Not Escaped

Assigner: 2N
Reserved: 19.09.2025 Published: 04.03.2026 Updated: 04.03.2026

: Improper Output Neutralization for Logs vulnerability in 2N telekomunikace 2N Access Commander on Linux allows Log Injection-Tampering-Forging.This issue affects 2N Access Commander: before 3.4.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor 2N Telekomunikace a.s.
Product 2N Access Commander
Versions Default: unaffected
  • affected from 0 to 3.4.2 (excl.)

References

Problem Types

  • CWE-117: Improper Output Neutralization for Logs CWE

Impacts

  • CAPEC-93 Log Injection-Tampering-Forging