10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
An OS command injection vulnerability exists due to incomplete
validation of user-supplied input. Validation fails to enforce
sufficient formatting rules, which could permit attackers to append
arbitrary data. This could allow an unauthenticated attacker to inject
arbitrary commands.
validation of user-supplied input. Validation fails to enforce
sufficient formatting rules, which could permit attackers to append
arbitrary data. This could allow an unauthenticated attacker to inject
arbitrary commands.
AI Analysis
OS command injection vulnerability due to incomplete validation of user input
Basic Information
ID
CVE-2025-64128
Source
icscert
Published
Nov 26, 2025 at 17:51
Modified
Nov 26, 2025 at 19:13
Affected Product
Vendor
Zenitel
Product
TCIV-3+
Affected Versions
Zenitel TCIV-3+ 0
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Zenitel
Product
TCIV-3+