CVE-2025-59783
OS Command Injection over API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.
| CWE | CWE-78 |
| Vendor | 2n telekomunikace a.s. |
| Product | 2n access commander |
| Published | Mar 4, 2026 |
| Last Updated | Mar 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for 2n telekomunikace a.s. 2n access commander
Be the first to know when new unknown vulnerabilities affecting 2n telekomunikace a.s. 2n access commander are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
2N Telekomunikace a.s. / 2N Access Commander
0 < 3.4.2