CVE-2025-59818

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
04/02/2026
Last modified:
11/02/2026

Description

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zenitel:tcis-3_firmware:*:*:*:*:*:*:*:* 9.2.3.3 (excluding)
cpe:2.3:h:zenitel:tcis-3:-:*:*:*:*:*:*:*