CVE-2026-25108
HIGH KEVFileZen - Command Injection
Title source: llmDescription
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Scores
CVSS v3
8.8
EPSS
0.0837
EPSS Percentile
92.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-02-24
VulnCheck KEV
2026-02-13
ENISA EUVD
EUVD-2026-6172
CWE
CWE-78
Status
published
Products (1)
soliton/filezen
4.2.1 - 5.0.11
Published
Feb 13, 2026
KEV Added
Feb 24, 2026
Tracked Since
Feb 18, 2026