CVE-2025-64128: Zenitel Tciv-3+

Critical severity, CVSS 10.0. EPSS: 2.4% chance of exploitation in the next 30 days.

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary commands.

Affected products

  • Zenitel Tciv-3+: up to and including 9.3.3.0

Published 2025-11-26. Last modified 2026-06-17.