CVE-2025-59818

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zenitel:tcis-3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zenitel:tcis-3:-:*:*:*:*:*:*:*

History

11 Feb 2026, 20:20

Type Values Removed Values Added
References () https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_notes - () https://wiki.zenitel.com/wiki/Turbine_9.3_-_Release_notes - Release Notes
References () https://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_Notes - () https://wiki.zenitel.com/wiki/VSF-Display_Series_9.3_Release_Notes - Release Notes
References () https://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_Notes - () https://wiki.zenitel.com/wiki/VSF-Fortitude6_9.3_Release_Notes - Release Notes
References () https://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_Notes - () https://wiki.zenitel.com/wiki/VSF-Fortitude8_9.3_Release_Notes - Release Notes
References () https://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_notes - () https://wiki.zenitel.com/wiki/ZIPS_9.3_-_Release_notes - Release Notes
References () https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf - () https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf - Vendor Advisory
First Time Zenitel
Zenitel tcis-3 Firmware
Zenitel tcis-3
CPE cpe:2.3:h:zenitel:tcis-3:-:*:*:*:*:*:*:*
cpe:2.3:o:zenitel:tcis-3_firmware:*:*:*:*:*:*:*:*

04 Feb 2026, 16:16

Type Values Removed Values Added
CWE CWE-77

04 Feb 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 11:16

Updated : 2026-02-11 20:20


NVD link : CVE-2025-59818

Mitre link : CVE-2025-59818

CVE.ORG link : CVE-2025-59818


JSON object : View

Products Affected

zenitel

  • tcis-3_firmware
  • tcis-3
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')