CVE-2026-25108: Soliton Systems K.K FileZen OS Command Injection Vulnerability
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Other sources
Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Soliton Systems K.K/FileZenfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Configuration
Disable the FileZen 'Antivirus Check Option' to prevent a logged-in user from sending a specially crafted HTTP request that could execute arbitrary OS commands.
FileZen Antivirus Check Option = disabled - Compensating control
Follow applicable BOD 22-01 guidance for cloud services to mitigate exposure of the FileZen deployment.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25108?
CVE-2026-25108 is classified as a critical severity vulnerability due to its potential for arbitrary OS command execution.
How do I fix CVE-2026-25108?
To fix CVE-2026-25108, ensure that the FileZen Antivirus Check Option is disabled and apply any security patches provided by FileZen.
Who is affected by CVE-2026-25108?
CVE-2026-25108 affects users of FileZen when the Antivirus Check Option is enabled.
What kind of attacks can CVE-2026-25108 enable?
CVE-2026-25108 allows attackers to execute arbitrary OS commands, which can lead to unauthorized access or control of the system.
Is CVE-2026-25108 being actively exploited?
As of now, there have been no confirmed reports of active exploitation for CVE-2026-25108, but caution is advised.