VYPR

Icx500 Firmware

by Zenitel

CVEs (2)

  • CVE-2025-64093CriJan 9, 2026
    risk 0.65cvss 10.0epss 0.01

    Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

  • CVE-2025-64092HigJan 9, 2026
    risk 0.49cvss 7.5epss 0.00

    This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database.