Security Advisory

CVE-2025-10659

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-30 20:00:53
Last updated 2025-09-30 20:41:17
Assigner icscert
State PUBLISHED

Description

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.