CVE-2025-64093

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
09/01/2026
Last modified:
10/02/2026

Description

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zenitel:icx500_firmware:*:*:*:*:*:*:*:* 1.4.3.3 (excluding)
cpe:2.3:h:zenitel:icx500:-:*:*:*:*:*:*:*
cpe:2.3:o:zenitel:icx510_firmware:*:*:*:*:*:*:*:* 1.4.3.3 (excluding)
cpe:2.3:h:zenitel:icx510:-:*:*:*:*:*:*:*