CVE-2025-59818 PUBLISHED

Authenticated Remote Code Execution via the file name of an uploaded file

Assigner: NCSC-NL
Reserved: 22.09.2025 Published: 04.02.2026 Updated: 04.02.2026

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Zenitel
Product TCIS-3+
Versions Default: unaffected
  • Version <9.2.3.3 is affected

References