CVE-2025-64127: Zenitel TCIV-3+ OS Command Injection
An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64127?
CVE-2025-64127 has been classified with a high severity due to its potential to allow unauthorized OS command execution.
How do I fix CVE-2025-64127?
To mitigate CVE-2025-64127, ensure proper input validation and sanitization for user-supplied parameters in the Zenitel TCIV-3+ application.
Who is affected by CVE-2025-64127?
CVE-2025-64127 affects the Zenitel TCIV-3+ product version up to and including 9.3.3.0.
What types of attacks can CVE-2025-64127 enable?
CVE-2025-64127 can enable unauthenticated attackers to execute arbitrary OS commands on affected systems.
Is there a patch available for CVE-2025-64127?
As of now, check with Zenitel for any available patches or updates that address CVE-2025-64127.