216.73.217.22

CVE-2025-59783

· Published 04/03/2026 16:16 · Modified 05/03/2026 15:05

Labels: CVE-2025-59783 2026-03-04CVE-2025-59783CWE-78be69f613-e5f6-419b-800c-30351aa8933c

Essential information

Published
04/03/2026 16:16
Modified
05/03/2026 15:05
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
be69f613-e5f6-419b-800c-30351aa8933c
NVD
View on NVD

Affected products (CPE)

ProductCPE
2n / access commander cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:*

References