CVE-2025-59815: Zenitel ICX500

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell access. Exploitation can compromise the device’s availability, confidentiality, and integrity.

Affected products

  • Zenitel ICX500: before 1.4.3.3 (fixed in 1.4.3.3)
  • Zenitel ICX510: before 1.4.3.3 (fixed in 1.4.3.3)

Published 2025-09-25. Last modified 2026-06-17.