CVE-2025-64092
HIGHZenitel ICX500 and ICX510 Firmware < 1.4.3.3 - Unauthenticated SQL Injection via GET Request Parameters
Title source: llmDescription
This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf
Scores
CVSS v3
7.5
EPSS
0.0037
EPSS Percentile
28.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (2)
zenitel/icx500_firmware
< 1.4.3.3
zenitel/icx510_firmware
< 1.4.3.3
Published
Jan 09, 2026
Tracked Since
Feb 18, 2026