Zenitel develops a focused line of critical infrastructure communication and emergency response systems, including its TCIS and ICX product lines, which serve institutional facilities such as hospitals, universities, and public-safety installations. Its vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity and concentrating in application-layer input-handling flaws—command injection, cross-site scripting, OS command injection, SQL injection, and unrestricted file upload—that are characteristic of web-facing administrative interfaces on such appliances. Defenders should prioritize patching this vendor's advisories, particularly for internet-accessible instances, and inventory affected deployments in critical infrastructure contexts; live severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zenitel over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59818CRITICAL This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file. | Feb 4, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-64093CRITICAL Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device. | Jan 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-64090HIGH This vulnerability allows authenticated attackers to execute commands via the hostname of the device. | Jan 9, 2026 | 8.8 | 29 | NO | NO |
CVE-2021-40845HIGH The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section at php/index.php. Neither the co | Sep 15, 2021 | 8.8 | 29 | NO | NO |
CVE-2025-64091HIGH This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. | Jan 9, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-64092HIGH This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database. | Jan 9, 2026 | 7.5 | 25 | NO | NO |
CVE-2018-19926MEDIUM Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO. | Dec 6, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-19927MEDIUM Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the goform/zForm_save_changes sip_nick paramet | Dec 6, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zenitel.
Media articles that mention a CVE ID that affects a product developed by Zenitel — matched by CVE ID, not by vendor name.