2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation.
This vulnerability can only be exploited after authenticating with administrator privileges.
References
| Link | Resource |
|---|---|
| https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf | Vendor Advisory |
Configurations
History
05 Mar 2026, 15:02
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:* | |
| References | () https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| First Time |
2n access Commander
2n |
04 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-04 16:16
Updated : 2026-03-05 15:02
NVD link : CVE-2025-59784
Mitre link : CVE-2025-59784
CVE.ORG link : CVE-2025-59784
JSON object : View
Products Affected
2n
- access_commander
CWE
CWE-117
Improper Output Neutralization for Logs
