CVE-2025-64127: Zenitel Tciv-3+
Critical severity, CVSS 10.0. EPSS: 2.4% chance of exploitation in the next 30 days.
An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.
Affected products
- Zenitel Tciv-3+: up to and including 9.3.3.0
Published 2025-11-26. Last modified 2026-06-17.