← Back to browse · API

CVE-2025-64128

Severity
CRITICAL
CVSS
10.0
EPSS
0.02435
Risk score
40.85
CISA KEV
No
PoC
No
Published
2025-11-26
Modified
2025-11-26
First seen
2026-08-07
Aliases
EUVD-2025-199740, GHSA-HHWP-X975-8R4G
Products
Zenitel:TCIV-3+ 0 ≤9.3.3.0
Sources
euvd EUVD-2025-199740

Description

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary commands.

References