2N Telekomunikace develops access-control and intercom solutions, with its vulnerability profile concentrated in products such as Access Commander and Access Unit firmware that manage physical and remote entry systems. The disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including improper certificate validation, path traversal, OS command injection, and exception-handling gaps that are characteristic of networked control and authentication systems. Defenders should prioritize patching for these access-control devices, particularly internet-exposed or remotely managed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2N Telekomunikace a.s. over time
Of all the CVEs published by 2N Telekomunikace a.s. as a CNA, 100.0% affect products that 2N Telekomunikace a.s. develops as a vendor.
Of all the CVEs published that affect products developed by 2N Telekomunikace a.s., 55.6% are self-published by 2N Telekomunikace a.s. as a CNA.
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59786CRITICAL 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. | Mar 4, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-59785HIGH Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption.
This vulnerability can onl | Mar 4, 2026 | 7.2 | 25 | NO | NO |
CVE-2025-59783HIGH API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection.
This vulnerability can onl | Mar 4, 2026 | 7.2 | 25 | NO | NO |
CVE-2025-59784HIGH 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation.
T | Mar 4, 2026 | 7.2 | 24 | NO | NO |
CVE-2024-47255HIGH In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary
code execution with root permission | Nov 5, 2024 | 7.8 | 22 | NO | NO |
CVE-2025-59787MEDIUM 2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving malformed or manipulated requests, indicating improper handl | Mar 4, 2026 | 6.5 | 21 | NO | NO |
CVE-2021-31399MEDIUM On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack. | Aug 13, 2021 | 5.9 | 21 | NO | NO |
CVE-2024-47254HIGH In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data Authenticity vulnerability could allow an attacker
to escalate their privileges and gain r | Nov 5, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-47253HIGH In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potent | Nov 5, 2024 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2N Telekomunikace a.s..
Media articles that mention a CVE ID that affects a product developed by 2N Telekomunikace a.s. — matched by CVE ID, not by vendor name.