CVE-2026-25108 is an OS command injection vulnerability in Soliton FileZen, allowing a logged-in user to execute arbitrary commands by sending a specially crafted HTTP request when the Antivirus Check Option is enabled. This vulnerability carries a high CVSS score of 8.8, indicating a critical impact with high confidentiality, integrity, and availability compromise, and requires only low privileges and no user interaction. It is actively exploited in the wild, as confirmed by CISA and evidenced by significant community discussion and media coverage, despite no public exploit code being readily available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.1, < 5.0.11CPE matchmatch criteria | cpe:2.3:a:soliton:filezen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.