CVE-2026-25108 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: February 13, 2026
FileZen - Command Injection
Overview
FileZen contains a command injection caused by improper input handling in the virus check option, letting logged-in users execute arbitrary OS commands remotely, exploit requires user to be logged in.
Severity & Score
Impact
Logged-in users can execute arbitrary OS commands, potentially leading to full system compromise.
Mitigation
Update to the latest version with the vulnerability fixed.
Social Media Activity(1 post)
📈 CVE Published in last 30 days (2026-01-30 - 2026-03-01) See more at https://secdb.nttzen.cloud/dashboard Total CVEs: 5003 Severity: - Critical: 448 - High: 1563 - Medium: 2229 - Low: 226 - None: 537 Status: - : 33 - Analyzed: 2258 - Awaiting Analysis: 2188 - Modified: 155 - Received: 89 - Rejected: 197 - Undergoing Analysis: 83 Top CNAs: - GitHub, Inc.: 907 - VulnCheck: 572 - VulDB: 519 - Patchstack: 385 - Wordfence: 361 - kernel.org: 259 - MITRE: 217 - Fortinet, Inc.: 102 - Intel Corporation: 84 - Apple Inc.: 76 Top Affected Products: - UNKNOWN: 2529 - Apple Macos: 64 - Mozilla Firefox: 54 - Mozilla Thunderbird: 51 - Apple Iphone Os: 49 - Apple Ipados: 49 - Openclaw: 35 - Imagemagick: 34 - Microsoft Windows Server 2025: 29 - Comodo Dome Firewall: 29 Top EPSS Score: - CVE-2026-1731 - 61.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1731) - CVE-2026-2329 - 41.14 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2329) - CVE-2026-22769 - 34.16 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-22769) - CVE-2026-25108 - 18.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-25108) - CVE-2026-2033 - 15.58 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2033) - CVE-2020-37123 - 12.89 % (https://secdb.nttzen.cloud/cve/detail/CVE-2020-37123) - CVE-2026-1603 - 11.74 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1603) - CVE-2026-1687 - 5.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1687) - CVE-2020-37088 - 4.95 % (https://secdb.nttzen.cloud/cve/detail/CVE-2020-37088) - CVE-2026-1207 - 4.78 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1207)
View original postRelated Resources
Details
- CVE ID
- CVE-2026-25108
- Severity
- High
- CVSS Score
- 8.8
- Type
- command_injection
- Status
- unconfirmed
- EPSS
- 1858.7%
- Social Posts
- 1
CWE
- CWE-78
CVSS Metrics
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H