Description
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.
INFO
Published Date :
2025-09-30T20:00:53.126Z
Last Modified :
2025-09-30T20:41:17.681Z
Source :
icscert
AFFECTED PRODUCTS
The following products are affected by CVE-2025-10659 vulnerability.
| Vendors | Products |
|---|---|
| Megasys |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-10659.