๐Ÿ” CVE Alert

CVE-2025-59783

UNKNOWN 0.0

OS Command Injection over API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.

CWE CWE-78
Vendor 2n telekomunikace a.s.
Product 2n access commander
Published Mar 4, 2026
Last Updated Mar 4, 2026
Stay Ahead of the Next One

Get instant alerts for 2n telekomunikace a.s. 2n access commander

Be the first to know when new unknown vulnerabilities affecting 2n telekomunikace a.s. 2n access commander are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

2N Telekomunikace a.s. / 2N Access Commander
0 < 3.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
2n.com: https://www.2n.com/en-GB/download/cve_2025_59783_acom_3_5_v1pdf