JPCERT/CC Warns of Active Exploits Targeting Critical FileZen Command Injection Flaw
ID: 595e0fe1-d5ea-53de-97dc-46d9edd9f2ee
STIX ID: report--595e0fe1-d5ea-53de-97dc-46d9edd9f2ee
Feed Name: securityonline.info
A critical OS command injection vulnerability (CVE-2026-25108, CVSS 8.8) in Soliton Systems' FileZen file transfer appliance can be exploited by an authenticated user sending a specially crafted HTTP request when the FileZen Antivirus Check Option is enabled, allowing arbitrary OS command execution and potential system takeover; multiple versions are affected (V5.0.0–V5.0.10 and V4.2.1–V4.2.8) and active exploitation has been reported, with a vendor patch released (upgrade to V5.0.11).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
