← Back to browse · API

CVE-2025-64127

Severity
CRITICAL
CVSS
10.0
EPSS
0.02435
Risk score
40.85
CISA KEV
No
PoC
No
Published
2025-11-26
Modified
2025-11-26
First seen
2026-08-07
Aliases
EUVD-2025-199741, GHSA-J74M-254J-542G
Products
Zenitel:TCIV-3+ 0 ≤9.3.3.0
Sources
euvd EUVD-2025-199741

Description

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

References