CVE-2025-59818
published 2026-02-04CVE-2025-59818: This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.51%
40.9th percentile
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zenitel | tcis-3 | — | — |
| zenitel | tcis-3_firmware | < 9.2.3.3 | 9.2.3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_noteshttps://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_Noteshttps://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_Noteshttps://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_Noteshttps://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_noteshttps://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf
2026-02-04
Published