๐Ÿ” CVE Alert

CVE-2025-59819

MEDIUM 6.5

Authenticated Arbitrary File Read via filepath parameter

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an internal system path.

Vendor zenitel
Product alphacom_xe_audio_server
Published Feb 20, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for zenitel alphacom_xe_audio_server

Be the first to know when new medium vulnerabilities affecting zenitel alphacom_xe_audio_server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

zenitel / alphacom_xe_audio_server
*

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zenitel.com: https://www.zenitel.com/sites/default/files/2025-12/A100K12333%20Zenitel%20Security%20Advisory.pdf wiki.zenitel.com: https://wiki.zenitel.com/wiki/AlphaCom_13.02_-_Release_Notes