CVE-2026-25108

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
13/02/2026
Last modified:
24/02/2026

Description

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:soliton:filezen:*:*:*:*:*:*:*:* 4.2.1 (including) 5.0.11 (excluding)