CVE-2025-64090 PUBLISHED

Authenticated Remote Code Execution in device hostname

Assigner: NCSC-NL
Reserved: 27.10.2025 Published: 09.01.2026 Updated: 09.01.2026

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Zenitel
Product TCIS-3+
Versions Default: unaffected
  • Version <9.2.3.3 is affected

References