Vulnerabilities in Zenitel
15 resultsVexday analysis
A Zenitel possui 14 vulnerabilidades registradas na base, sendo 7 classificadas como críticas, mas nenhuma está sob exploração ativa (KEV), o que reduz o risco imediato. A fraqueza dominante é a CWE-77 (injeção de comandos), padrão que demanda atenção em validação de entrada. Sem publicações nos últimos 90 dias, o cenário atual é estável, mas a presença de vulnerabilidades críticas mantém a necessidade de avaliação e mitigação em plano de remediação.
CVE-2025-64128CRITICALZenitel TCIV-3+ OS Command InjectionEPSS 2.4%CVE-2025-64127CRITICALZenitel TCIV-3+ OS Command InjectionEPSS 2.4%CVE-2025-64126CRITICALZenitel TCIV-3+ OS Command InjectionEPSS 2.4%CVE-2025-64130CRITICALZenitel TCIV-3+ Cross-site ScriptingEPSS 0.9%CVE-2025-64093CRITICALUnauthenticated Remote Code Execution via the device hostnameEPSS 0.8%CVE-2025-59818CRITICALAuthenticated Remote Code Execution via the file name of an uploaded fileEPSS 0.5%CVE-2025-64129HIGHZenitel TCIV-3+ Out-of-bounds WriteEPSS 0.4%CVE-2025-64092HIGHUnauthenticated SQL injection via GET request parametersEPSS 0.4%CVE-2025-64090CRITICALAuthenticated Remote Code Execution in device hostnameEPSS 0.4%CVE-2025-59819MEDIUMAuthenticated Arbitrary File Read via filepath parameterEPSS 0.4%CVE-2025-64091HIGHAuthenticated Remote Code Execution in the NTP-configurationEPSS 0.4%CVE-2025-59814HIGHUnauthenticated SQL-injection in password fieldEPSS 0.3%CVE-2025-59815HIGHAuthenticated Remote Code Execution in the Billing Administration portalEPSS 0.3%CVE-2025-59817HIGHAuthenticated Remote Code Execution in zForm_auto_configEPSS 0.2%CVE-2025-59816HIGHAuthenticated Union based SQL-injection in the search input fieldEPSS 0.2%