PatchSiren

Zenitel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Zenitel CVE published 2025-11-26

CVE-2025-64130

A reflected cross-site scripting vulnerability exists in Zenitel TCIV-3+, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser. The CVE record was published on 2025-11-26T18:15:50.243Z and was last modified on 2026-09-26T00:10:00.127Z. The NVD entry is currently Deferred. Defenders should verify exposure of TCIV-3+ systems, especially those in industrial control envi [truncated]