CVE 8.1 HIGH

Authenticated Union based SQL-injection in the search input field_CVE-2025-59816

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.

Basic Information

ID CVE-2025-59816
Source NCSC-NL
Published Sep 25, 2025 at 19:30

Affected Product

Vendor Zenitel
Product ICX500
Version <1.4.3.3
Affected Versions Zenitel ICX500 <1.4.3.3
Zenitel ICX510 <1.4.3.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.