CVE-2026-25108
Description
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Summary dbcve.org
FileZen contains an OS command injection vulnerability that allows authenticated users to execute arbitrary OS commands through specially crafted HTTP requests when the Antivirus Check Option is enabled. The vulnerability stems from improper input validation in the antivirus scanning functionality, enabling an attacker with valid credentials to inject and execute malicious commands on the underlying operating system.
Mitigation
Disable the FileZen Antivirus Check Option if not essential for business operations; otherwise, apply vendor-provided patches immediately and implement strict input validation on all user-supplied parameters. Consider network segmentation to limit exposure and audit user privileges.