CVE-2025-59816

HIGH

Zenitel ICX500 and ICX510 < 1.4.3.3 - SQL Injection and Plaintext Password Disclosure

Title source: llm
STIX 2.1

Description

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.

References (2)

Core 2
Core References

Scores

CVSS v3 7.3
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
Zenitel/ICX500 <1.4.3.3
Zenitel/ICX510 <1.4.3.3
Published Sep 25, 2025
Tracked Since Feb 18, 2026