CVE-2025-64128: Zenitel TCIV-3+ OS Command Injection
An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64128?
CVE-2025-64128 has been classified with a high severity due to the potential for OS command injection that could lead to unauthorized system access.
How do I fix CVE-2025-64128?
To fix CVE-2025-64128, ensure that the affected Zenitel TCIV-3+ system is updated to the latest firmware version that addresses the input validation issues.
What are the potential impacts of CVE-2025-64128?
If exploited, CVE-2025-64128 could allow an unauthenticated attacker to execute arbitrary commands on the vulnerable system.
Who is affected by CVE-2025-64128?
CVE-2025-64128 specifically affects the Zenitel TCIV-3+ product running firmware version 9.3.3.0 or earlier.
Is CVE-2025-64128 easy to exploit?
Yes, CVE-2025-64128 presents an easy exploitation path for attackers due to inadequate validation of user inputs.