HIGH

CVE-2026-25108

Soliton Filezen 2026-02-13 CVSS v3.1
CVSS
8.8
KEV

Description

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

Summary dbcve.org

FileZen contains an OS command injection vulnerability that allows authenticated users to execute arbitrary OS commands through specially crafted HTTP requests when the Antivirus Check Option is enabled. The vulnerability stems from improper input validation in the antivirus scanning functionality, enabling an attacker with valid credentials to inject and execute malicious commands on the underlying operating system.

Mitigation

Disable the FileZen Antivirus Check Option if not essential for business operations; otherwise, apply vendor-provided patches immediately and implement strict input validation on all user-supplied parameters. Consider network segmentation to limit exposure and audit user privileges.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

5.07%
Probability of exploitation in next 30 days
91.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE