CVE-2025-59817
8.4Zenitel · TCIS-3+
Zenitel TCIS-3+ devices contain a command injection vulnerability (CWE-77) allowing authenticated attackers with high privileges to execute arbitrary commands on the underlying system.
Executive summary
An authenticated command injection vulnerability in Zenitel TCIS-3+ devices poses a significant risk of full system compromise for affected units.
Vulnerability
This is a command injection vulnerability (CWE-77) occurring due to improper neutralization of special elements. The CVSS vector (PR:H) indicates that an attacker must possess high-level administrative privileges to successfully trigger the command execution.
Business impact
The vulnerability carries a CVSS score of 8.4, reflecting a high risk due to the potential for total system compromise. Successful exploitation grants an attacker the ability to execute arbitrary commands, which could lead to unauthorized system control, data exfiltration, or complete device disruption, causing significant operational downtime for affected communication infrastructure.
Remediation
Immediate Action: Update all Zenitel TCIS-3+ devices to firmware version 9.2.3.3 or later as specified in the vendor advisory.
Proactive Monitoring: Review system access logs for unauthorized administrative activities or unusual process execution patterns that deviate from standard device operation.
Compensating Controls: Restrict management access to the device to trusted IP addresses only and ensure that administrative credentials are rotated and managed through secure, centralized identity providers.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the severity of the potential impact, administrators should prioritize updating all vulnerable TCIS-3+ units to the patched version immediately. Ensure that all administrative interfaces are segmented from public-facing networks to mitigate the risk of unauthorized access by malicious actors.