VDB
CVE-2025-59816
CVE-2025-59816
PUBLISHED
CVSS 7.300000190734863 HIGH
This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.
EPSS 0.03% · 9.2th percentile
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.03%
9.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zenitel | ICX510 | <1.4.3.3 |
| Zenitel | ICX500 | * |
Timeline
- Sep 25, 2025 CVE Published
- Sep 26, 2025 EPSS Score
- Sep 26, 2025 PoC Published
- Sep 26, 2025 CVE Updated
- Oct 3, 2025 EPSS Score
- Oct 4, 2025 Coalition ESS Score
- Oct 6, 2025 Coalition ESS Score
- Oct 10, 2025 EPSS Score
- Oct 16, 2025 EPSS Score
- Oct 23, 2025 EPSS Score
- Oct 30, 2025 EPSS Score
- Nov 6, 2025 EPSS Score
References
- Zenitel url
- Zenitel patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-59816 advisory