CVE-2025-59814 is a critical SQL injection vulnerability affecting Zenitel ICX500 and ICX510 Gateway devices, specifically within the Billing Admin endpoint. This flaw allows unauthenticated attackers on the local network to read the entire Billing Admin database, posing a significant risk to data confidentiality, integrity, and availability. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable with low attack complexity and no user interaction required. While there is currently no public exploit code or evidence of active exploitation, its high FAUCET Risk Score of 83/100 indicates a substantial potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zenitel | ICX500 | <1.4.3.3CNA affecteddefault unaffected | |
| Zenitel | ICX510 | <1.4.3.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.