logo

FileZen Flaw Allows Attackers to Execute Commands Remotely

ID: bb987958-3b2e-5d98-9885-998e535821b4

STIX ID: report--bb987958-3b2e-5d98-9885-998e535821b4

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Divya

...
...

A high-severity OS command-injection vulnerability (CVE-2026-25108) affecting Soliton Systems' FileZen (versions V5.0.0–V5.0.10 and V4.2.1–V4.2.8) allows authenticated attackers to execute arbitrary OS commands when the Antivirus Check Option is enabled; active exploitation has been observed. The vendor released patch V5.0.11 and JPCERT/CC issued guidance—organizations should apply the update immediately and review authentication and HTTP request logs for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.