CVE-2025-64093: Unauthenticated Remote Code Execution via the device hostname
Published Jan 9, 2026
·Updated
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.
Affected Software
4 affected components
All of the following
Zenitel Icx500 Firmware<1.4.3.3
Zenitel ICX500
All of the following
Zenitel Icx510 Firmware<1.4.3.3
Zenitel ICX510
Event History
Jan 9, 2026
CVE Published
via MITRE·10:04 AM
Data Sourced
via MITRE·10:04 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64093?
CVE-2025-64093 is classified as a critical vulnerability due to its potential for unauthenticated remote code execution.
2
How do I fix CVE-2025-64093?
To mitigate CVE-2025-64093, update the Zenitel ICX500 and ICX510 firmware to version 1.4.3.3 or higher.
3
What devices are affected by CVE-2025-64093?
CVE-2025-64093 affects Zenitel ICX500 and ICX510 devices running firmware versions below 1.4.3.3.
4
Is CVE-2025-64093 an authenticated or unauthenticated vulnerability?
CVE-2025-64093 is an unauthenticated vulnerability, allowing attackers to exploit it without any credentials.
5
What are the potential impacts of CVE-2025-64093?
Exploitation of CVE-2025-64093 can lead to complete system compromise through remote code execution.