CVE-2026-25108
CVE-2026-25108
In short
FileZen has a flaw that allows a logged-in user to run unauthorized commands on the server by sending specially crafted requests when the Antivirus Check feature is enabled. This lets attackers take control of the system.
Technical detail
OS command injection vulnerability (CWE-78) in FileZen's Antivirus Check feature allows authenticated users to execute arbitrary OS commands via maliciously crafted HTTP requests. Exploitation requires valid user credentials and the feature to be enabled; successful exploitation grants command execution with application privileges.
Summary generated and translated by AI from the official description.
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Soliton Systems K.K. · FileZenWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →