This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
References
| Link | Resource |
|---|---|
| https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_notes | Release Notes |
| https://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_Notes | Release Notes |
| https://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_Notes | Release Notes |
| https://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_Notes | Release Notes |
| https://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_notes | Release Notes |
| https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
11 Feb 2026, 20:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_notes - Release Notes | |
| References | () https://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_Notes - Release Notes | |
| References | () https://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_Notes - Release Notes | |
| References | () https://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_Notes - Release Notes | |
| References | () https://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_notes - Release Notes | |
| References | () https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf - Vendor Advisory | |
| First Time |
Zenitel
Zenitel tcis-3 Firmware Zenitel tcis-3 |
|
| CPE | cpe:2.3:h:zenitel:tcis-3:-:*:*:*:*:*:*:* cpe:2.3:o:zenitel:tcis-3_firmware:*:*:*:*:*:*:*:* |
04 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-77 |
04 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-04 11:16
Updated : 2026-02-11 20:20
NVD link : CVE-2025-59818
Mitre link : CVE-2025-59818
CVE.ORG link : CVE-2025-59818
JSON object : View
Products Affected
zenitel
- tcis-3_firmware
- tcis-3
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
