CVE-2026-25108
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
13/02/2026
Last modified:
13/02/2026
Description
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



