Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in FileZen Antivirus Check Option Allowing Arbitrary Command Execution |
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in FileZen Antivirus Check Option Allowing Arbitrary Command Execution |
Tue, 24 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soliton
Soliton filezen |
|
| CPEs | cpe:2.3:a:soliton:filezen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Soliton
Soliton filezen |
|
| Metrics |
cvssV3_1
|
Tue, 24 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Tue, 24 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soliton Systems K.k.
Soliton Systems K.k. filezen |
|
| Vendors & Products |
Soliton Systems K.k.
Soliton Systems K.k. filezen |
Fri, 13 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileZen contains an OS command injection vulnerability. When FileZen virus check option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command. | FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command. |
Fri, 13 Feb 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileZen contains an OS command injection vulnerability. When FileZen virus check option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-02-26T14:44:20.718Z
Reserved: 2026-01-30T11:03:04.608Z
Link: CVE-2026-25108
Updated: 2026-02-13T13:08:28.786Z
Status : Analyzed
Published: 2026-02-13T04:15:53.410
Modified: 2026-02-24T21:38:18.607
Link: CVE-2026-25108
No data.
OpenCVE Enrichment
Updated: 2026-04-22T20:00:08Z