Junglewise Threat Intelligence

CVE-2026-25108: Soliton Systems FileZen OS command injection in Antivirus Check Option

CVE-2026-25108 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2026-02-24

Executive brief

Soliton FileZen, a secure file transfer and sharing appliance, contains a critical security flaw that allows an attacker to take control of the system. By sending a specifically formatted web request, a logged-in user can execute unauthorized commands on the underlying operating system. This could lead to the theft of sensitive files, service disruption, or a total compromise of the appliance. This vulnerability is currently being exploited in the wild.

Technical details

An OS command injection vulnerability (CWE-78) exists in Soliton FileZen within the Antivirus Check Option component. The flaw is triggered when the system fails to properly neutralize special elements in an HTTP request, allowing a remote authenticated user with low privileges to execute arbitrary commands on the host operating system. The attack vector is network-based and does not require user interaction, though it does require valid login credentials. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Users should update to version 5.0.11 or later.

Affected products

  • Soliton Systems K.K. FileZen 4.2.1 to 5.0.10

Timeline

  • 2026-02-12: disclosed
  • 2026-02-24: kev added: Added to CISA Known Exploited Vulnerabilities catalog.