logo

JPCERT/CC Warns of Active Exploits Targeting Critical FileZen Command Injection Flaw

ID: 595e0fe1-d5ea-53de-97dc-46d9edd9f2ee

STIX ID: report--595e0fe1-d5ea-53de-97dc-46d9edd9f2ee

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical OS command injection vulnerability (CVE-2026-25108, CVSS 8.8) in Soliton Systems' FileZen file transfer appliance can be exploited by an authenticated user sending a specially crafted HTTP request when the FileZen Antivirus Check Option is enabled, allowing arbitrary OS command execution and potential system takeover; multiple versions are affected (V5.0.0–V5.0.10 and V4.2.1–V4.2.8) and active exploitation has been reported, with a vendor patch released (upgrade to V5.0.11).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.