CVE-2025-59816

high

Description

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.

References

https://wiki.zenitel.com/wiki/ICX_1.4.3.X_-_Release_Notes

https://wiki.zenitel.com/wiki/Downloads#ICX-AlphaCom_System

Details

Source: Mitre, NVD

Published: 2025-09-25

Updated: 2025-09-26

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Severity: High

EPSS

EPSS: 0.00028