CVE-2025-59814: Zenitel ICX500

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read the entire contents of the Billing Admin database.

Affected products

  • Zenitel ICX500: before 1.4.3.3 (fixed in 1.4.3.3)
  • Zenitel ICX510: before 1.4.3.3 (fixed in 1.4.3.3)

Published 2025-09-25. Last modified 2026-06-17.