7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database.
Basic Information
ID
CVE-2025-64092
Source
NCSC-NL
Published
Jan 9, 2026 at 10:03
Affected Product
Vendor
Zenitel
Product
ICX500
Version
<1.4.3.3
Affected Versions
Zenitel ICX500 <1.4.3.3
Zenitel ICX510 <1.4.3.3
Zenitel ICX510 <1.4.3.3