CVE-2025-10659: Megasys Telenium Online Web Application:
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.
Affected products
- Megasys Telenium Online Web Application:: up to and including 8.4.21
Published 2025-09-30. Last modified 2026-06-17.