CVE Watchtower


← Back to CVE List

CVE-2025-10659NVD

Description

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.
Severity Level
CRITICAL (9.3)
Published Date
30/09/2025
Last Modified
30/09/2025
Exploitation Status
????