Access Commander
Vendor:
First CVE: Nov 5, 2024 · Active for 1 year
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Access Commander over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2024
20 months ago
Most Recent CVE
Mar 4, 2026
142 days ago
CVE Severity & Scoring
Access Commander8 CVEs
13%
75%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High5 (62.5%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59786CRITICAL 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application. | Mar 4, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-59785HIGH Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption.
This vulnerability can onl | Mar 4, 2026 | 7.2 | 25 | NO | NO |
CVE-2025-59783HIGH API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection.
This vulnerability can onl | Mar 4, 2026 | 7.2 | 25 | NO | NO |
CVE-2025-59784HIGH 2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation.
T | Mar 4, 2026 | 7.2 | 24 | NO | NO |
CVE-2024-47255HIGH In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary
code execution with root permission | Nov 5, 2024 | 7.8 | 22 | NO | NO |
CVE-2025-59787MEDIUM 2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving malformed or manipulated requests, indicating improper handl | Mar 4, 2026 | 6.5 | 21 | NO | NO |
CVE-2024-47254HIGH In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data Authenticity vulnerability could allow an attacker
to escalate their privileges and gain r | Nov 5, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-47253HIGH In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potent | Nov 5, 2024 | 7.2 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Access Commander
Top CWEs
Versions
No cataloged versions.