← back
CVE-2026-25108

CVE-2026-25108

CVSS 8.7 HIGHEPSS 5.0%● KEVCWE-78
In short

FileZen has a flaw that allows a logged-in user to run unauthorized commands on the server by sending specially crafted requests when the Antivirus Check feature is enabled. This lets attackers take control of the system.

Technical detail

OS command injection vulnerability (CWE-78) in FileZen's Antivirus Check feature allows authenticated users to execute arbitrary OS commands via maliciously crafted HTTP requests. Exploitation requires valid user credentials and the feature to be enabled; successful exploitation grants command execution with application privileges.

Summary generated and translated by AI from the official description.
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →