Executive Summary
In November 2025, Zenitel disclosed multiple critical vulnerabilities affecting its TCIV-3+ intercom systems, widely deployed in communications-critical infrastructure worldwide. Security researchers from Claroty Team82 identified three separate OS command injection flaws (CVE-2025-64126, -64127, -64128), as well as a severe out-of-bounds write and a reflected cross-site scripting vulnerability. These issues allowed threat actors to remotely execute arbitrary code or cause denial-of-service conditions without authentication, putting operational technology environments at significant risk of disruption or compromise. The vulnerabilities require only low-complexity attacks and no user interaction, amplifying their business impact.
This incident highlights the ongoing critical importance of securing industrial control system components exposed to remote exploitation. With threat actors increasingly targeting IoT and OT devices in critical communications infrastructure, these types of vulnerabilities are seeing a dramatic rise globally, and patching urgency is at an all-time high.
Why This Matters Now
The Zenitel TCIV-3+ vulnerabilities are urgent because they allow unauthenticated, remote compromise of core communications equipment, affecting critical infrastructure on a global scale. With exploitation tools evolving rapidly and attacks on OT/ICS environments intensifying, addressing these zero-day risks is essential to prevent major operational and safety impacts.
Attack Path Analysis
The attacker remotely exploited an OS command injection vulnerability on the Zenitel TCIV-3+ device to gain initial access over the network. Upon compromise, they executed arbitrary commands with elevated privileges provided by the vulnerable process. Using their foothold, the attacker attempted to move laterally across the network to reach other devices or systems. Establishing command and control, they maintained persistence and control by leveraging covert communication channels. The attacker prepared for and possibly conducted data exfiltration or furthered their objectives using outbound channels. Ultimately, the attacker could disrupt operations, execute denial-of-service attacks, or leverage the system for further assaults, leading to severe impact.
Kill Chain Progression
Initial Compromise
Description
Exploitation of the OS command injection or XSS vulnerabilities via unauthenticated remote access to the device's network interface.
Related CVEs
CVE-2025-64126
CVSS 9.8An OS command injection vulnerability in Zenitel TCIV-3+ allows unauthenticated attackers to execute arbitrary commands remotely.
Affected Products:
Zenitel TCIV-3+ – < 9.3.3.0
Exploit Status:
no public exploitCVE-2025-64127
CVSS 9.8An OS command injection vulnerability in Zenitel TCIV-3+ allows unauthenticated attackers to execute arbitrary commands remotely.
Affected Products:
Zenitel TCIV-3+ – < 9.3.3.0
Exploit Status:
no public exploitCVE-2025-64128
CVSS 9.8An OS command injection vulnerability in Zenitel TCIV-3+ allows unauthenticated attackers to execute arbitrary commands remotely.
Affected Products:
Zenitel TCIV-3+ – < 9.3.3.0
Exploit Status:
no public exploitCVE-2025-64129
CVSS 7.6An out-of-bounds write vulnerability in Zenitel TCIV-3+ allows remote attackers to crash the device.
Affected Products:
Zenitel TCIV-3+ – < 9.3.3.0
Exploit Status:
no public exploitCVE-2025-64130
CVSS 9.8A reflected cross-site scripting vulnerability in Zenitel TCIV-3+ allows remote attackers to execute arbitrary JavaScript on the victim's browser.
Affected Products:
Zenitel TCIV-3+ – < 9.3.3.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: Unix Shell
Exploitation for Client Execution
Abuse Elevation Control Mechanism
Endpoint Denial of Service
Network Share Discovery
Input Capture: Keylogging
Input Capture: Web Portal Capture
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Address Common Coding Vulnerabilities in Software-Development Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 15
CISA Zero Trust Maturity Model 2.0 – Implement Secure Application Development and Threat Mitigation
Control ID: Application Workload Security
NIS2 Directive – Incident Handling and Security by Design
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical vulnerability in Zenitel TCIV-3+ communication systems enables remote command injection, threatening network infrastructure operations and encrypted traffic protection capabilities.
Utilities
Industrial control systems vulnerability allows unauthenticated remote exploitation, compromising power grid operations, SCADA systems, and critical infrastructure segmentation controls.
Transportation
Communication system vulnerabilities expose transportation networks to denial-of-service attacks, affecting traffic management systems and operational technology security protocols.
Government Administration
CISA advisory highlights critical infrastructure risks requiring immediate patching, enhanced network segmentation, and improved east-west traffic monitoring capabilities.
Sources
- Zenitel TCIV-3+https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-03Verified
- Zenitel TCIV-3+ Firmware Downloadshttps://wiki.zenitel.com/wiki/Downloads#Station_and_Device_Firmware_Package_.28VS-IS.29Verified
- CVE-2025-64126 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-64126Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, micro-segmentation, and strong egress controls would have prevented or detected unauthorized access, lateral movement, and outbound command & control in the attack chain. CNSF-aligned capabilities, including threat detection, workload isolation, encrypted traffic controls, and runtime enforcement, would have significantly reduced the attack surface and limited blast radius.
Control: Zero Trust Segmentation
Mitigation: Minimized exposed attack surface to only required sources.
Control: Threat Detection & Anomaly Response
Mitigation: Identified abnormal system command executions and privilege changes.
Control: East-West Traffic Security
Mitigation: Detected and blocked unauthorized internal communications and lateral traversal.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked unauthorized outbound command and control traffic.
Control: Cloud Firewall (ACF)
Mitigation: Prevented suspicious data egress to unauthorized external endpoints.
Limited attacker persistence and facilitated rapid detection of destructive actions.
Impact at a Glance
Affected Business Functions
- Communication Systems
- Emergency Response
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive communication data due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Apply Zero Trust segmentation to restrict network access to all ICS/OT endpoints and minimize exposed interfaces.
- • Enforce granular east-west and egress security policies to contain lateral movement and prevent unauthorized outbound traffic.
- • Deploy automated threat detection and anomaly response systems to quickly identify and respond to suspicious behavior on critical devices.
- • Ensure traffic inspection and micro-segmentation controls are used to observe and control internal and external traffic flows.
- • Continuously update and monitor workloads for vulnerabilities and maintain strong workload isolation using CNSF-aligned controls.



