CVE-2025-64126: Zenitel Tciv-3+

Critical severity, CVSS 10.0. EPSS: 2.4% chance of exploitation in the next 30 days.

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker to inject arbitrary commands.

Affected products

  • Zenitel Tciv-3+: up to and including 9.3.3.0

Published 2025-11-26. Last modified 2026-06-17.