CVE-2025-59783Disclosure(2n / access_commander)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • access_commander

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
access_commander

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 103-0403-05
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-043
Disclosure2General1
2026-03-051
Disclosure1
Full discourse4 posts
  • ThreatCluster@threatcluster
    Disclosure

    2N Access Commander 3.4.1-3.4.2 affected by two API flaws: CVE-2025-59783 enables OS command injection and CVE-2025-59785 weakens backup encryption, both require admin authentication. https://threatcluster.io/cluster/critical-vulnerabilities-found-in-2n-access-commander-api-2848adf9

    Post summary

    The post discloses two API flaws in 2N Access Commander—CVE‑2025‑59783 allows OS command injection, and CVE‑2025‑59785 weakens backup encryption—both requiring admin credentials, with no mention of exploitation or patching.

    0000080
    91 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-59783 API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnera… https://www.cve.org/CVERecord?id=CVE-2025-59783 ----- Traducción: CVE-2025-59783 API… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑59783, an OS command injection vulnerability in 2N Access Commander 3.4.1, providing only basic technical details and a link to the CVE record.

    0000094
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59783 API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnera… https://www.cve.org/CVERecord?id=CVE-2025-59783

    Post summary

    The snippet announces CVE-2025-59783, identifying OS command injection through an unvalidated API endpoint in 2N Access Commander 3.4.1 and directs readers to the official CVE record for details.

    00000218
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-59783 - OS Command Injection over API Intel Report: https://ift.tt/CjzFGTH

    Post summary

    The alert notes CVE‑2025‑59783 as an OS Command Injection via an API but offers no PoC, exploit code, patch, or evidence of active exploitation.

    00000100
    344 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App2naccess_commander---

Explore more