FileZen Flaw Allows Attackers to Execute Commands Remotely
ID: bb987958-3b2e-5d98-9885-998e535821b4
STIX ID: report--bb987958-3b2e-5d98-9885-998e535821b4
Feed Name: GBHackers
Threat Score
A high-severity OS command-injection vulnerability (CVE-2026-25108) affecting Soliton Systems' FileZen (versions V5.0.0–V5.0.10 and V4.2.1–V4.2.8) allows authenticated attackers to execute arbitrary OS commands when the Antivirus Check Option is enabled; active exploitation has been observed. The vendor released patch V5.0.11 and JPCERT/CC issued guidance—organizations should apply the update immediately and review authentication and HTTP request logs for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
