CVE-2025-59783

HIGH WAF: High
CVSS 7.2 Published: 2026-03-04
CWE-78

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
2naccess_commanderup to 3.4.2

References

Back to CVE Database