← volver
CVE-2025-59814

Unauthenticated SQL-injection in password field

CVSS 8.8 HIGHEPSS 0.3%CWE-89
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
25 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read the entire contents of the Billing Admin database.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H