CVE-2025-59818

CRITICAL WAF: High
CVSS 9.8 Published: 2026-02-04
CWE-77

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
zeniteltcis-3_firmwareup to 9.2.3.3

References

Back to CVE Database