Vulnerability Description
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zenitel | Tcis-3 Firmware | < 9.2.3.3 |
| Zenitel | Tcis-3 | - |
Related Weaknesses (CWE)
References
- https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_notesRelease Notes
- https://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_NotesRelease Notes
- https://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_NotesRelease Notes
- https://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_NotesRelease Notes
- https://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_notesRelease Notes
- https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20SecurVendor Advisory
FAQ
What is CVE-2025-59818?
CVE-2025-59818 is a vulnerability with a CVSS score of 10.0 (CRITICAL). This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
How severe is CVE-2025-59818?
CVE-2025-59818 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-59818?
Check the references section above for vendor advisories and patch information. Affected products include: Zenitel Tcis-3 Firmware, Zenitel Tcis-3.