CVE-2025-64093 PUBLISHED

Unauthenticated Remote Code Execution via the device hostname

Assigner: NCSC-NL
Reserved: 27.10.2025 Published: 09.01.2026 Updated: 09.01.2026

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Zenitel
Product ICX500
Versions Default: unaffected
  • Version <1.4.3.3 is affected
Vendor Zenitel
Product ICX510
Versions Default: unaffected
  • Version <1.4.3.3 is affected

References