Home

Description

2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability can only be exploited after authenticating with administrator privileges.

PUBLISHED Reserved 2025-09-19 | Published 2026-03-04 | Updated 2026-03-04 | Assigner 2N




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-117: Improper Output Neutralization for Logs

Product status

Default status
unaffected

Any version before 3.4.2
affected

References

www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf vendor-advisory

cve.org (CVE-2025-59784)

nvd.nist.gov (CVE-2025-59784)

Download JSON