CVE 9.3 CRITICAL

MegaSys Enterprises Telenium Online Web Application OS Command Injection_CVE-2025-10659

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.

Basic Information

ID CVE-2025-10659
Source icscert
Published Sep 30, 2025 at 20:00

Affected Product

Vendor MegaSys
Product Telenium Online Web Application:
Affected Versions MegaSys Telenium Online Web Application: 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.