CVE-2025-64090

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
09/01/2026
Last modified:
12/02/2026

Description

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zenitel:tcis-3_firmware:*:*:*:*:*:*:*:* 9.2.3.3 (excluding)
cpe:2.3:h:zenitel:tcis-3:-:*:*:*:*:*:*:*