Zenitel kayıtları
zenitel üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-64093İstismar yok | Unauthenticated Remote Code Execution via the device hostnamezenitel · icx500 firmware · CWE-77 | Kritik9,8 | — | %0,8 | 9 Oca 2026 |
39İzleyin | CVE-2025-59818İstismar yok | Authenticated Remote Code Execution via the file name of an uploaded filezenitel · tcis-3 firmware · CWE-77 | Kritik9,8 | — | %0,6 | 4 Şub 2026 |
36İzleyin | CVE-2021-40845Kavram kanıtı | The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts zenitel · alphacom xe audio server · CWE-434 | Yüksek8,8 | — | %4,7 | 15 Eyl 2021 |
35İzleyin | CVE-2025-64090İstismar yok | Authenticated Remote Code Execution in device hostnamezenitel · tcis-3 firmware · CWE-77 | Yüksek8,8 | — | %0,4 | 9 Oca 2026 |
35İzleyin | CVE-2025-64091İstismar yok | Authenticated Remote Code Execution in the NTP-configurationzenitel · tcis-3 firmware · CWE-78 | Yüksek8,8 | — | %0,4 | 9 Oca 2026 |
30İzleyin | CVE-2025-64092İstismar yok | Unauthenticated SQL injection via GET request parameterszenitel · icx500 firmware · CWE-89 | Yüksek7,5 | — | %0,4 | 9 Oca 2026 |
24İzleyin | CVE-2018-19926İstismar yok | Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.zenitel · ip-stationweb firmware · CWE-79 | Orta6,1 | — | %0,7 | 6 Ara 2018 |
19İzleyin | CVE-2018-19927İstismar yok | Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the gozenitel · ip-stationweb firmware · CWE-79 | Orta4,8 | — | %0,6 | 6 Ara 2018 |
- CVE-2025-6409339İzleyin
Unauthenticated Remote Code Execution via the device hostname
KritikCVSS 9,8İstismar yokEPSS %1zenitel · icx500 firmware9 Oca 2026
- CVE-2025-5981839İzleyin
Authenticated Remote Code Execution via the file name of an uploaded file
KritikCVSS 9,8İstismar yokEPSS %1zenitel · tcis-3 firmware4 Şub 2026
- CVE-2021-4084536İzleyin
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts
YüksekCVSS 8,8Kavram kanıtıEPSS %5zenitel · alphacom xe audio server15 Eyl 2021
- CVE-2025-6409035İzleyin
Authenticated Remote Code Execution in device hostname
YüksekCVSS 8,8İstismar yokEPSS %0zenitel · tcis-3 firmware9 Oca 2026
- CVE-2025-6409135İzleyin
Authenticated Remote Code Execution in the NTP-configuration
YüksekCVSS 8,8İstismar yokEPSS %0zenitel · tcis-3 firmware9 Oca 2026
- CVE-2025-6409230İzleyin
Unauthenticated SQL injection via GET request parameters
YüksekCVSS 7,5İstismar yokEPSS %0zenitel · icx500 firmware9 Oca 2026
- CVE-2018-1992624İzleyin
Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.
OrtaCVSS 6,1İstismar yokEPSS %1zenitel · ip-stationweb firmware6 Ara 2018
- CVE-2018-1992719İzleyin
Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the go
OrtaCVSS 4,8İstismar yokEPSS %1zenitel · ip-stationweb firmware6 Ara 2018