CVE-2025-64126: Zenitel Tciv-3+
Critical severity, CVSS 10.0. EPSS: 2.4% chance of exploitation in the next 30 days.
An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker to inject arbitrary commands.
Affected products
- Zenitel Tciv-3+: up to and including 9.3.3.0
Published 2025-11-26. Last modified 2026-06-17.