CVE-2025-59817: Zenitel Tcis-3+
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.
Affected products
- Zenitel Tcis-3+: before 9.2.3.3 (fixed in 9.2.3.3)
Published 2025-09-25. Last modified 2026-06-17.