CVE-2025-59816 HIGH

CVE-2025-59816: Authenticated Union based SQL-injection in the search input field

Vendor Zenitel
Product ICX500
Weakness CWE-89 · SQLi
Published September 25, 2025
Last update September 26, 2025

CVSS base score

7.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.

Key dates

02Disclosure timeline

September 25, 2025 CVE published
September 26, 2025 Record updated