Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-59816 1 Zenitel 2 Icx500, Icx510 2025-09-26 7.3 High
This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.
CVE-2025-59814 1 Zenitel 2 Icx500, Icx510 2025-09-26 8.8 High
This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read the entire contents of the Billing Admin database.
CVE-2025-59815 1 Zenitel 2 Icx500, Icx510 2025-09-26 8.4 High
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell access. Exploitation can compromise the device’s availability, confidentiality, and integrity.