CVE-2025-10659 Details
Description
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.
A vulnerability has been identified in the MegaSys Telenium Online Web Application, specifically in versions through 8.4.21. The issue arises from a PHP endpoint that is accessible to unauthenticated users. This endpoint improperly processes user-supplied input, allowing for the injection of arbitrary operating system commands via a crafted HTTP request. The vulnerability stems from an insecure regular expression validation, which fails to adequately sanitize the input. Exploitation of this flaw could lead to remote code execution on the server, executed under the web application service account.
Users are advised to visit the MegaSys support page for instructions on applying the available fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2025CISA-ADP
Assessed Sep 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.portal.megasys.com/ | [email protected] | Permission RequiredVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-273-01 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MegaSys Telenium Online Web Application | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | New CVE Received | [email protected] |
Volerion