This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
References
| Link | Resource |
|---|---|
| https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_notes | Release Notes |
| https://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_Notes | Release Notes |
| https://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_Notes | Release Notes |
| https://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_Notes | Release Notes |
| https://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_notes | Release Notes |
| https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-02-04 11:16
Updated : 2026-06-17 09:46
NVD link : CVE-2025-59818
Mitre link : CVE-2025-59818
CVE.ORG link : CVE-2025-59818
JSON object : View
Products Affected
zenitel
- tcis-3
- tcis-3_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
