CVE-2025-64091

8.6

Zenitel · TCIS-3+

A command injection vulnerability in Zenitel TCIS-3+ devices allows attackers to execute arbitrary commands via the NTP configuration settings.

Executive summary

A high-severity command injection vulnerability in Zenitel TCIS-3+ devices could allow unauthorized attackers to execute arbitrary system commands, posing a significant risk to device integrity.

Vulnerability

The vulnerability exists within the NTP configuration functionality of the device, permitting command injection. Although the initial report suggests authenticated access, the CVSS vector indicates an attack vector that does not require prior authentication or user interaction.

Business impact

The ability to execute arbitrary commands on network-connected devices can lead to full system compromise, unauthorized data access, or the potential for lateral movement within the network. With a CVSS score of 8.6, this vulnerability is classified as High severity and requires immediate attention to prevent potential service disruption or malicious exploitation of the infrastructure.

Remediation

Immediate Action: Update all Zenitel TCIS-3+ devices to firmware version 9.2.3.3 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor network traffic for unusual outbound requests originating from intercom or security devices, specifically looking for attempts to interact with the NTP configuration interface.

Compensating Controls: Implement strict network segmentation to isolate these devices from critical segments and restrict access to the device management interface to authorized administrative IP addresses only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the High severity of this vulnerability and the potential for remote command execution, organizations must prioritize patching all affected Zenitel TCIS-3+ units. Failure to remediate could leave devices vulnerable to unauthorized control, necessitating a swift deployment of the provided firmware update to maintain the security posture of the environment.

More Zenitel CVEs

Sources