PT-2025-48137 · Zenitel · Zenitel Tciv-3+
Published
2025-11-25
·
Updated
2025-12-01
·
CVE-2025-64126
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zenitel TCIV-3+ versions prior to 9.3.3.0
Description
An OS command injection issue exists due to insufficient input validation. The application accepts user-supplied input without verifying it as a valid IP address or filtering potentially harmful characters. This allows an unauthenticated attacker to inject arbitrary commands. The vulnerability could allow a remote attacker to execute commands on the system, potentially gaining full control of the device. This could lead to eavesdropping on conversations, manipulation of access control systems, or use of the device as an entry point into a network. Additional issues include cross-site scripting (XSS) and a buffer overflow that can cause the device to crash.
Recommendations
Update Zenitel TCIV-3+ to a version later than 9.3.3.0.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenitel Tciv-3+