ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59818
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

NVD description · AI analysis pending
9.8<1%
  • zenitel tcis-3 firmware
CVE-2025-64093
+1 in the same advisory: …64092
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

NVD description · AI analysis pending
9.8
group max
<1%
  • zenitel icx500 firmware
  • zenitel icx510 firmware
CVE-2025-64090
+1 in the same advisory: …64091
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

NVD description · AI analysis pending
8.8<1%
  • zenitel tcis-3 firmware
CVE-2021-40845
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index

The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the content nor extension of the uploaded files is checked, allowing execution of PHP code under the /cmd directory.

NVD description · AI analysis pending
8.85% PoC ×3
  • zenitel alphacom xe audio server
CVE-2018-19926
+1 in the same advisory: …19927
Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.

Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • zenitel ip-stationweb firmware